Lucene search

K
osvGoogleOSV:GHSA-JRQM-V8CV-53WW
HistoryMay 13, 2022 - 1:08 a.m.

Matrix Synapse Predictable Secret Key

2022-05-1301:08:16
Google
osv.dev
5
matrix synapse
version 0.34.0.1
macaroon secret key
authentication parameter
remote attackers
impersonation
software

EPSS

0.006

Percentile

79.2%

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.