Gomatrixserverlib Server-Side Request Forgery (SSRF) on redirects and federation
Moderate severity
GitHub Reviewed
Published
Jan 16, 2025
in
matrix-org/gomatrixserverlib
•
Updated Jan 17, 2025
Package
Affected versions
<= 0.0.0-20250106190028-bf86bc98b879
Patched versions
0.0.0-20250116181547-c4f1e01eab0d
Description
Published by the National Vulnerability Database
Jan 16, 2025
Published to the GitHub Advisory Database
Jan 16, 2025
Reviewed
Jan 16, 2025
Last updated
Jan 17, 2025
Impact
Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
Patches
c4f1e01eab0dd435709ad15463ed38a079ad6128 fixes this issue.
Workarounds
Use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
References
N/A
References