CVE-2024-52602

CVSS 3.1 Score 5 of 10 (medium)

Details

Published Jan 16, 2025
CWE ID 918

Summary

CVE-2024-52602 is a server-side request forgery vulnerability affecting Matrix Media Repo (MMR).This issue allows an attacker to make unauthorized requests to the repository, potentially serving content from a private network that MMR can access. Affected versions are below v1.3.8. To mitigate risk for those unable to upgrade immediately, implementing firewall rules or using a transparent proxy to restrict MMR's contacts may offer a workaround.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share