Skip to main content

Permissive Cross-domain Policy with Untrusted Domains

CVE-2024-41659

Severity High
Score 8.6/10

Summary

The Memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos versions 0.20.0 through 0.20.1, where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to "true". This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • NONE
  • HIGH
  • NONE

CWE-942 - Permissive Cross-domain Policy with Untrusted Domains

The software uses a cross-domain policy file that includes domains that should not be trusted.

Advisory Timeline

  • Published