t2bot matrix-media-repo
cpe:2.3:a:matrix-media-repo_project:matrix-media-repo:*:*:*:*:*:*:*
- < 1.3.8
A denial-of-service vulnerability has been identified in Matrix Media Repo (MMR) versions prior to 1.3.8. This issue arises because MMR can parse large amounts of JSON data returned from other servers, leading to excessive memory consumption and exhaustion of available resources. The vulnerability can be exploited during normal operation when MMR processes requests to resource owners that return substantial JSON payloads.
Exploitation of this vulnerability can cause memory exhaustion, leading to a denial-of-service condition where the application becomes unresponsive or unavailable.
Users are advised to upgrade to Matrix Media Repo version 1.3.8. For those unable to upgrade, forward proxies can be configured to block requests to unsafe hosts. Additionally, MMR processes can be set with memory limits and configured to auto-restart. Running multiple MMR processes concurrently can also help mitigate the impact of a restart on users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.