CVE-2024-41659

HIGH

Memos < 0.21.0 - Permissive CORS Policy

Title source: rule
STIX 2.1

Description

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.

Scores

CVSS v3 8.1
EPSS 0.0019
EPSS Percentile 40.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-942
Status published
Products (2)
usememos/memos < 0.21.0
usememos/memos 0 - 0.21.0Go
Published Aug 20, 2024
Tracked Since Feb 18, 2026