PT-2026-60789 · Git+1 · Dendrite
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dendrite versions prior to 0.13.9
Description
A server-side request forgery (SSRF) issue allows unauthenticated attackers to force the server to establish outbound TLS connections to arbitrary hosts and ports. This is achieved by providing an unvalidated
serverName parameter to the legacy media download endpoint. Attackers can use distinguishable error response classes and internal IP addresses leaked in error messages to conduct blind port scanning and map the internal network topology.Recommendations
Update to version 0.13.9 or later.
As a temporary mitigation, restrict access to the legacy media download endpoint.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dendrite