memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-04-19 15:15
Updated : 2024-04-19 16:19
NVD link : CVE-2024-29028
Mitre link : CVE-2024-29028
CVE.ORG link : CVE-2024-29028
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)