Permissive Cross-domain Policy with Untrusted Domains
CVE-2024-41659
Summary
The Memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos versions 0.20.0 through 0.20.1, where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to "true". This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- NONE
CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
The software uses a cross-domain policy file that includes domains that should not be trusted.
References
Advisory Timeline
- Published