CVE-2024-52602
CVSS 3.1 Score 5 of 10 (medium)
Details
Published Jan 16, 2025
CWE ID 918
Summary
CVE-2024-52602 is a server-side request forgery vulnerability affecting Matrix Media Repo (MMR).This issue allows an attacker to make unauthorized requests to the repository, potentially serving content from a private network that MMR can access. Affected versions are below v1.3.8. To mitigate risk for those unable to upgrade immediately, implementing firewall rules or using a transparent proxy to restrict MMR's contacts may offer a workaround.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.