PT-2022-28111 · Unknown · Usememos/Memos

Boojack

·

Published

2022-12-28

·

Updated

2024-08-21

·

CVE-2022-4810

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions usememos/memos versions prior to 0.9.1
Description The issue is related to improper access control in the usememos/memos GitHub repository. A user can view any content from private memos from other users via the API. This affects versions prior to 0.9.1.
Recommendations For versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the API endpoint that allows viewing private memos until a patch is available.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-4810
GHSA-QF9Q-3WWX-8QJV
GO-2022-1263

Affected Products

Usememos/Memos