icon

We found results for “

CVE-2024-41659

Good to know:

icon

Date: August 20, 2024

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Permissive Cross-domain Security Policy with Untrusted Domains

CWE-942

Top Fix

icon

Upgrade Version

Upgrade to version github.com/usememos/memos - v0.21.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us