CVE-2019-5885
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable val
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
HIGH · CVSS 7.5
EPSS 0.00773
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0