PT-2022-27987 · Unknown · Usememos/Memos

Published

2022-12-23

·

Updated

2024-08-21

·

CVE-2022-4683

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.0
Description The issue is related to a sensitive cookie in an HTTPS session without the 'Secure' attribute. This affects an open-source, self-hosted memo hub with knowledge management and socialization capabilities. The missing Secure cookie attribute makes it vulnerable to session hijacking.
Recommendations For versions prior to 0.9.0, update to version 0.9.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive cookies until the update is applied.

Exploit

Fix

Missing Encryption of Sensitive Data

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4683
GHSA-QCW2-492V-57XJ
GO-2022-1192

Affected Products

Usememos/Memos