Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cqm-mgv9-vv9j

Опубликовано: 05 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.1

Описание

memos vulnerable to Server-Side Request Forgery and Cross-site Scripting

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.

Пакеты

Наименование

github.com/usememos/memos

go
Затронутые версииВерсия исправления

< 0.22.0

0.22.0

EPSS

Процентиль: 81%
0.01593
Низкий

6.9 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-918

Связанные уязвимости

CVSS3: 6.1
nvd
почти 2 года назад

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.

EPSS

Процентиль: 81%
0.01593
Низкий

6.9 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-918