CVE-2024-41659
HIGHDescription
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set to true. This may allow an attacking website to make a cross-origin request, allowing the attacker to read private information or make privileged changes to the system as the vulnerable user account. This vulnerability is fixed in 0.21.0.
Is your site exposed to CVE-2024-41659?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| usememos | memos |
References
Frequently Asked Questions
What is CVE-2024-41659? +
How severe is CVE-2024-41659? +
What products are affected by CVE-2024-41659? +
How do I check if I'm vulnerable to CVE-2024-41659? +
Related Vulnerabilities
Rob -- W / cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to …
claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due to improper …
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to …
The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page …
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected …
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross-origin resource sharing (CORS). Exploiting this vulnerability …