CVE-2019-5885: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only
  • Matrix Synapse: before 0.34.0.1 (fixed in 0.34.0.1)

Published 2019-03-21. Last modified 2026-06-17.