PT-2022-28104 · Unknown · Usememos/Memos

Published

2022-12-28

·

Updated

2024-08-20

·

CVE-2022-4803

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.1
Description The issue is related to improper access control, allowing for authorization bypass through a user-controlled key. This affects the usememos/memos GitHub repository. No information is provided about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the repository to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-4803
GHSA-MFMP-8MQG-Q4WM
GO-2023-1291

Affected Products

Usememos/Memos