PYSEC-2019-187
Dashboard / Vulnerabilities / PYSEC-2019-187
PYSEC-2019-187
Summary:
Details: Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
References: https://matrix.org/blog/2019/01/15/further-details-on-critical-security-update-in-synapse-affecting-all-versions-prior-to-0-34-1-cve-2019-5885/, https://matrix.org/blog/2019/01/10/critical-security-update-synapse-0-34-0-1-synapse-0-34-1-1/, https://lists.fedoraproject.org/archives/list/[email protected]/message/VMCLO5PUPBA756UKY72PKUWL4RRM4W6K/, https://lists.fedoraproject.org/archives/list/[email protected]/message/32Y6KD3OAHCG5P33HC2QEX3NUZOSXCGZ/, https://github.com/advisories/GHSA-jrqm-v8cv-53ww
Affected packages
Package
Name: matrix-synapse
Purl: pkg:pypi/matrix-synapse
Affected ranges
Type: ECOSYSTEM
Events:
