Affected by GO-2023-2036
and 6 other vulnerabilities
GO-2023-2036: usememos/memos vulnerable to privilege escalation in github.com/usememos/memos
GO-2023-2038: Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos in github.com/usememos/memos
GO-2023-2065: Cross-Site Request Forgery (CSRF) in usememos/memos in github.com/usememos/memos
GO-2024-3046: memos vulnerable to Server-Side Request Forgery in /api/resource in github.com/usememos/memos
GO-2024-3047: memos vulnerable to Server-Side Request Forgery in /o/get/httpmeta in github.com/usememos/memos
GO-2024-3049: memos vulnerable to Server-Side Request Forgery and Cross-site Scripting in github.com/usememos/memos
GO-2024-3088: memos CORS Misconfiguration in server.go (GHSL-2024-034) in github.com/usememos/memos
directory
Version:
v0.12.2
Opens a new window with list of versions in this module.
Published: Apr 16, 2023
License: MIT
Opens a new window with license information.
Directories
¶
Package getter is using to get resources from url.
|
Package getter is using to get resources from url. |
|
|
oauth2
Package oauth2 is the plugin for OAuth2 Identity Provider.
|
Package oauth2 is the plugin for OAuth2 Identity Provider. |
|
|
storage
|
|
|
|
Click to show internal directories.
Click to hide internal directories.