Description
Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0090 | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access. |
Github GHSA |
GHSA-4ff6-858j-r822 | Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation |
References
History
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access. | |
| Title | Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-12T20:31:20.951Z
Reserved: 2024-11-14T15:05:46.768Z
Link: CVE-2024-52594
Updated: 2025-02-12T20:26:07.772Z
Status : Deferred
Published: 2025-01-16T19:15:28.480
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52594
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA