Access Token Management Flaw in Memos Note-Taking Service
CVE-2024-21635
7.1HIGH
What is CVE-2024-21635?
Memos, a privacy-oriented note-taking application, has a vulnerability that allows Access Tokens to remain valid after a user changes their password. This flaw means that if an account is compromised, the bad actor retains access unless the user manually deletes the valid Access Tokens associated with their account. The generic description of these tokens complicates the identification of unauthorized access. To mitigate this risk, it is recommended that Memos implement a feature where all Access Tokens are revoked upon a password change, ensuring that all sessions are terminated and users must re-authenticate.
Affected Version(s)
memos <= 0.18.1
