High severity7.5OSV Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2019-5885
CVE-2019-5885
Description
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
matrix-synapsePyPI | < 0.34.0.1 | 0.34.0.1 |
Affected products
6cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*range: <0.34.0.1
- (no CPE)range: hhs-1, hhs-2, hhs-3, …
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 0.34.0.1+ 1 more
- (no CPE)range: < 0.34.0.1
- (no CPE)range: < 1.43.0-1.1
Patches
Vulnerability mechanics
References
15- github.com/advisories/GHSA-jrqm-v8cv-53wwghsaADVISORY
- matrix.org/blog/2019/01/10/critical-security-update-synapse-0-34-0-1-synapse-0-34-1-1/nvdVendor Advisory
- matrix.org/blog/2019/01/15/further-details-on-critical-security-update-in-synapse-affecting-all-versions-prior-to-0-34-1-cve-2019-5885/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2019-5885ghsaADVISORY
- github.com/matrix-org/synapse/blob/67f9e5293ea6650b2ec284c0b7503f3f3eade94b/docs/changelogs/CHANGES-pre-1.0.mdghsaWEB
- github.com/matrix-org/synapse/issues/4664ghsaWEB
- github.com/matrix-org/synapse/pull/4315ghsaWEB
- github.com/matrix-org/synapse/pull/4373ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2019-187.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/32Y6KD3OAHCG5P33HC2QEX3NUZOSXCGZghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/VMCLO5PUPBA756UKY72PKUWL4RRM4W6KghsaWEB
- matrix.org/blog/2019/01/10/critical-security-update-synapse-0-34-0-1-synapse-0-34-1-1ghsaWEB
- matrix.org/blog/2019/01/15/further-details-on-critical-security-update-in-synapse-affecting-all-versions-prior-to-0-34-1-cve-2019-5885ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/32Y6KD3OAHCG5P33HC2QEX3NUZOSXCGZ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMCLO5PUPBA756UKY72PKUWL4RRM4W6K/nvd
News mentions
0No linked articles in our index yet.