First published: Thu Jan 16 2025(Updated: )
### Impact Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. ### Patches c4f1e01eab0dd435709ad15463ed38a079ad6128 fixes this issue. ### Workarounds Use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access. ### References N/A
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/matrix-org/gomatrixserverlib | <=0.0.0-20250106190028-bf86bc98b879 | 0.0.0-20250116181547-c4f1e01eab0d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-4ff6-858j-r822 is classified as a moderate risk due to its potential for server-side request forgery.
To fix GHSA-4ff6-858j-r822, update gomatrixserverlib to version 0.0.0-20250116181547-c4f1e01eab0d or later.
GHSA-4ff6-858j-r822 affects gomatrixserverlib versions up to and including 0.0.0-20250106190028-bf86bc98b879.
A potential workaround for GHSA-4ff6-858j-r822 is to implement a local firewall to restrict access to sensitive network segments.
Yes, GHSA-4ff6-858j-r822 can compromise network security by allowing unauthorized access to private network resources.