Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2620 | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0. |
Github GHSA |
GHSA-p4fx-qf2h-jpmj | memos CORS Misconfiguration in server.go (GHSL-2024-034) |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:usememos:memos:*:*:*:*:*:*:*:* |
Thu, 22 Aug 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0. |
| References |
|
Wed, 21 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Usememos
Usememos memos |
|
| CPEs | cpe:2.3:a:usememos:memos:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Usememos
Usememos memos |
|
| Metrics |
ssvc
|
Tue, 20 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. | |
| Title | GHSL-2024-034: memos CORS Misconfiguration in server.go | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-09T19:15:30.589Z
Reserved: 2024-07-18T15:21:47.482Z
Link: CVE-2024-41659
Updated: 2024-08-21T13:25:28.790Z
Status : Analyzed
Published: 2024-08-20T20:15:08.207
Modified: 2025-07-10T15:36:42.900
Link: CVE-2024-41659
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA