CVE-2024-52594
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-52594 is a newly identified vulnerability affecting the Go library for matrix federation, named Gomatrixserverlib. This issue involves server-side request forgery, allowing unauthorized access to content from a private network that the affected server can reach. Under specific conditions, an attacker can exploit this vulnerability to serve malicious content. The issue has been addressed in commit `c4f1e01`. It is strongly recommended that users upgrade to the patched version to mitigate this risk. For those unable to upgrade, implementing a local firewall to restrict network access to the affected service is advised.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.