CVE-2024-52602
MEDIUM5.0EPSS 0.12%Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation in github.com/t2bot/matrix-media-repo
Published: 1/16/2025Modified: 3/3/2026
Description
Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation in github.com/t2bot/matrix-media-repo
Affected packages (2)
- Go/github.com/t2bot/matrix-media-repofrom 0, < 1.3.8
- Go/github.com/t2bot/matrix-media-repofrom 0, < 1.3.8
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.0 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
References (8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-52602
- PATCHhttps://github.com/t2bot/matrix-media-repo
- WEBhttps://github.com/t2bot/matrix-media-repo/releases/tag/v1.3.8
- WEBhttps://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-r6jg-jfv6-2fjv
- WEBhttps://learn.snyk.io/lesson/ssrf-server-side-request-forgery
- WEBhttps://owasp.org/www-community/attacks/Server_Side_Request_Forgery
- WEBhttps://pkg.go.dev/vuln/GO-2025-3399
- WEBhttps://www.agwa.name/blog/post/preventing_server_side_request_forgery_in_golang