First published: Sun Dec 25 2022(Updated: )
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos prior to 0.9.1.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/usememos/memos | <=0.9.0 | 0.9.1 |
Usememos Memos | <0.9.1 | |
<0.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-4734.
The title of the vulnerability is 'Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository usememos/memos'.
The description of the vulnerability is that the usememos/memos 0.9.0 and prior has an endpoint that leaks user information like names, email, role, and OpenID to an authenticated user.
The severity of CVE-2022-4734 is high with a severity value of 4.3.
To fix CVE-2022-4734, you should update to version 0.9.1 of usememos/memos or later.