Skip to main content

Improper Verification of Source of a Communication Channel

CVE-2022-4848

Severity Medium
Score 5.7/10

Summary

Improper Verification of Source of a Communication Channel in usememos/memos prior to 0.9.1. This has the same fix as CVE-2022-4844, CVE-2022-4845, CVE-2022-4846, CVE-2022-4847, CVE-2022-4849, and CVE-2022-4850.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • LOW
  • NONE
  • NONE

CWE-940 - Improper Verification of Source of a Communication Channel

The software establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Advisory Timeline

  • Published