ZeroHour

CVE-2019-5885

CVSS 3.0
7.5 high
EPSS
2%p83
Published
()
Modified
Description

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

Vendors
matrixfedoraproject
Products
synapse, fedora
Weakness
CWE-330
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.