GHSL-2024-034: memos CORS Misconfiguration in server.go
CVE-2024-41659
8.1HIGH
What is CVE-2024-41659?
The Memos note-taking service, designed for privacy-conscious users, is affected by a cross-origin resource sharing (CORS) misconfiguration. In versions 0.20.1 and earlier, the Access-Control-Allow-Credentials header is improperly set to true, allowing any origin to make cross-origin requests. This vulnerability enables attackers to potentially access private user data or execute actions as the legitimate user. The issue has been addressed in version 0.21.0, which users are recommended to update to in order to protect their information and maintain the integrity of their accounts.
Affected Version(s)
memos <= 0.20.1