PT-2024-22681 · Memos · Memos

Kevin Stubbings

+1

·

Published

2024-04-18

·

Updated

2025-07-07

·

CVE-2024-29028

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions memos versions 0.13.2 through 0.16.0
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability. It exists at the "/o/get/httpmeta" API endpoint, allowing unauthenticated users to enumerate the internal network and receive limited HTML values in JSON form.
Recommendations For memos versions 0.13.2 through 0.16.0, update to version 0.16.1 to resolve the issue. As a temporary workaround, consider restricting access to the "/o/get/httpmeta" API endpoint until the update is applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-29028
GHSA-6FCF-G3MP-XJ2X
GO-2024-3047

Affected Products

Memos