445
VMScore

CVE-2019-5885

Published: 21/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Matrix Synapse prior to 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote malicious users to impersonate users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

matrix synapse

fedoraproject fedora 28

fedoraproject fedora 29

Vendor Advisories

matrix-synapse before 0341 is vulnerable to private key recovery as synapse will attempt to derive a secret key from other secrets specified in the configuration file for "macaroon_secret_key" However, in all versions of Synapse up to and including 0340, this process was faulty and a predictable value was used instead ...