VDB
KO

PYSEC-2019-187

Details

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0 Fixed in: 0.34.0.1
Fix pip install --upgrade 'matrix-synapse>=0.34.0.1'

References