CVE-2024-29028

MEDIUM5.8EPSS 6.1%

memos vulnerable to Server-Side Request Forgery in /o/get/httpmeta

Published: 8/5/2024Modified: 8/6/2024
Also known as:GHSA-6fcf-g3mp-xj2xGO-2024-3047

Description

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

References (5)