memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.
History

Thu, 22 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
Description memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.
References

Wed, 21 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Usememos
Usememos memos
CPEs cpe:2.3:a:usememos:memos:-:*:*:*:*:*:*:*
Vendors & Products Usememos
Usememos memos
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Aug 2024 20:00:00 +0000

Type Values Removed Values Added
Description memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account.
Title GHSL-2024-034: memos CORS Misconfiguration in server.go
Weaknesses CWE-942
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-20T19:54:08.182Z

Updated: 2024-08-22T15:27:22.743Z

Reserved: 2024-07-18T15:21:47.482Z

Link: CVE-2024-41659

cve-icon Vulnrichment

Updated: 2024-08-21T13:25:28.790Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-20T20:15:08.207

Modified: 2024-08-22T16:15:08.993

Link: CVE-2024-41659

cve-icon Redhat

No data.