Improper Verification of Source of a Communication Channel
CVE-2022-4848
Summary
Improper Verification of Source of a Communication Channel in usememos/memos prior to 0.9.1. This has the same fix as CVE-2022-4844, CVE-2022-4845, CVE-2022-4846, CVE-2022-4847, CVE-2022-4849, and CVE-2022-4850.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- LOW
- NONE
- NONE
CWE-940 - Improper Verification of Source of a Communication Channel
The software establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
References
Advisory Timeline
- Published