Description
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2545 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file. |
Github GHSA |
GHSA-9cqm-mgv9-vv9j | memos vulnerable to Server-Side Request Forgery and Cross-site Scripting |
References
History
Thu, 02 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usememos
Usememos memos |
|
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:03:51.649Z
Reserved: 2024-03-14T16:59:47.612Z
Link: CVE-2024-29029
Updated: 2024-04-19T18:10:36.654Z
Status : Analyzed
Published: 2024-04-19T16:15:09.853
Modified: 2025-01-02T20:46:24.867
Link: CVE-2024-29029
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA