PT-2025-2932 · Unknown+1 · Gomatrixserverlib+1

S7Evink

·

Publicado

2025-01-16

·

Atualizado

2025-01-30

·

CVE-2024-52594

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gomatrixserverlib (affected versions not specified)
Description Gomatrixserverlib is a Go library for matrix federation. It is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The issue allows access to certain content under specific conditions. Users are advised to upgrade to fix the issue. As a mitigation measure, users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
Recommendations For all affected versions, users are advised to upgrade to a version that includes the commit c4f1e01 to fix the issue. As a temporary workaround, consider using a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access, until a patch is applied.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-52594
GHSA-4FF6-858J-R822
GO-2025-3396
OPENSUSE-SU-2025:14704-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Produtos afetados

Gomatrixserverlib
Suse