← voltar
CVE-2024-29029mediumexploração observadaCWE-79CWE-918

memos vulnerable to an SSRF in /o/get/image

50Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 6.1epss 1.1%
da publicação à arma
Publicada no NVD19 de abr.
VulnCheck+524d
probabilidade de exploração
1.1%top 38% das CVEs
exploração observada
simVulnCheck
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
usememos · memos