CVE-2024-52602: Matrix Media Repo (MMR) allows Server-Side Request Forgery (SSRF) on redirects and federation
(updated )
Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
References
- github.com/advisories/GHSA-r6jg-jfv6-2fjv
- github.com/t2bot/matrix-media-repo
- github.com/t2bot/matrix-media-repo/releases/tag/v1.3.8
- github.com/t2bot/matrix-media-repo/security/advisories/GHSA-r6jg-jfv6-2fjv
- learn.snyk.io/lesson/ssrf-server-side-request-forgery
- nvd.nist.gov/vuln/detail/CVE-2024-52602
- owasp.org/www-community/attacks/Server_Side_Request_Forgery
- pkg.go.dev/vuln/GO-2025-3399
- www.agwa.name/blog/post/preventing_server_side_request_forgery_in_golang
Detect and mitigate CVE-2024-52602 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →