PT-2025-2933 · Unknown+1 · Matrix Media Repo+1

S7Evink

·

Published

2025-01-16

·

Updated

2025-08-20

·

CVE-2024-52602

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Matrix Media Repo (MMR) versions prior to 1.3.8
Description Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. This issue allows MMR to serve content from a private network, potentially exposing sensitive information. Users are advised to upgrade to a fixed version.
Recommendations For versions prior to 1.3.8, upgrade to version 1.3.8 or later to resolve the issue. As a temporary workaround, consider restricting which hosts MMR is allowed to contact via local firewall rules or a transparent proxy to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-52602
GHSA-R6JG-JFV6-2FJV
GO-2025-3399
OPENSUSE-SU-2025:14704-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Matrix Media Repo
Suse