Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
History

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Description Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
Title Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-16T18:57:29.333Z

Updated: 2025-02-12T20:31:20.951Z

Reserved: 2024-11-14T15:05:46.768Z

Link: CVE-2024-52594

cve-icon Vulnrichment

Updated: 2025-02-12T20:26:07.772Z

cve-icon NVD

Status : Received

Published: 2025-01-16T19:15:28.480

Modified: 2025-01-16T19:15:28.480

Link: CVE-2024-52594

cve-icon Redhat

No data.