Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib
Vulnerability Description
Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
gomatrixserverlib 代码问题漏洞
Vulnerability Description
gomatrixserverlib是Matrix基金会的一个 Go 库。用于矩阵服务器所需的常用功能。 Gomatrixserverlib存在代码问题漏洞,该漏洞源于容易受到服务器端请求伪造的攻击。
CVSS Information
N/A
Vulnerability Type
N/A