memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Aug 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0. |
References |
|
Wed, 21 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Usememos
Usememos memos |
|
CPEs | cpe:2.3:a:usememos:memos:-:*:*:*:*:*:*:* | |
Vendors & Products |
Usememos
Usememos memos |
|
Metrics |
ssvc
|
Tue, 20 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. | |
Title | GHSL-2024-034: memos CORS Misconfiguration in server.go | |
Weaknesses | CWE-942 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-20T19:54:08.182Z
Updated: 2024-08-22T15:27:22.743Z
Reserved: 2024-07-18T15:21:47.482Z
Link: CVE-2024-41659
Vulnrichment
Updated: 2024-08-21T13:25:28.790Z
NVD
Status : Awaiting Analysis
Published: 2024-08-20T20:15:08.207
Modified: 2024-08-22T16:15:08.993
Link: CVE-2024-41659
Redhat
No data.