MEDIUM6.1
GHSA-9w8x-5hv5-r6gw
Cross Site Scripting in usememos/memos
Quick fix
GHSA-9w8x-5hv5-r6gw — github.com/usememos/memos: upgrade to the fixed version with the command below.
go get github.com/usememos/memos@v0.10.4-0.20230211093429-b11d2130a084Details
All versions of the package github.com/usememos/memos/server prior to 0.11.0 are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/usememos/memos
Introduced in:
0Fixed in: 0.10.4-0.20230211093429-b11d2130a084Fix
go get github.com/usememos/memos@v0.10.4-0.20230211093429-b11d2130a084References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25978[ADVISORY]
- https://github.com/usememos/memos/issues/1026[WEB]
- https://github.com/usememos/memos/commit/b11d2130a084385eb65c3761a3c841ebe9f81ae8[WEB]
- https://pkg.go.dev/vuln/GO-2023-1566[WEB]
- https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMUSEMEMOSMEMOSSERVER-3319070[WEB]
- github.com/usememos/memos[PACKAGE]