PT-2022-28101 · Unknown · Usememos/Memos

Published

2022-12-28

·

Updated

2024-08-21

·

CVE-2022-4800

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.1
Description The issue concerns an improper verification of the source of a communication channel. This affects the usememos/memos GitHub repository. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to communication channels to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-4800
GHSA-MFVQ-M3JJ-8864
GO-2022-1240

Affected Products

Usememos/Memos