PT-2025-2932 · Unknown+1 · Gomatrixserverlib+1

S7Evink

·

Published

2025-01-16

·

Updated

2025-01-30

·

CVE-2024-52594

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gomatrixserverlib (affected versions not specified)
Description Gomatrixserverlib is a Go library for matrix federation. It is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The issue allows access to certain content under specific conditions. Users are advised to upgrade to fix the issue. As a mitigation measure, users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
Recommendations For all affected versions, users are advised to upgrade to a version that includes the commit c4f1e01 to fix the issue. As a temporary workaround, consider using a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access, until a patch is applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-52594
GHSA-4FF6-858J-R822
GO-2025-3396
OPENSUSE-SU-2025:14704-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Gomatrixserverlib
Suse