—
GO-2022-1191
usememos/memos vulnerable to account takeover due to improper access control in github.com/usememos/memos
Quick fix
GO-2022-1191 — github.com/usememos/memos: upgrade to the fixed version with the command below.
go get github.com/usememos/memos@v0.9.0Details
usememos/memos vulnerable to account takeover due to improper access control in github.com/usememos/memos
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/usememos/memos
Introduced in:
0Fixed in: 0.9.0Fix
go get github.com/usememos/memos@v0.9.0References
- https://github.com/advisories/GHSA-w57v-6xp4-rm2v[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-4689[ADVISORY]
- https://github.com/usememos/memos/commit/dca35bde877aab6e64ef51b52e590b5d48f692f9[FIX]
- https://github.com/usememos/memos/pull/831[FIX]
- https://huntr.dev/bounties/a78c4326-6e7b-47fe-aa82-461e5c12a4e3[WEB]