CVE-2024-29028: GHSL-2023-154_GHSL-2023-156: Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) in memos API - CVE-2024-29028, CVE-2024-29029, CVE-2024-29030
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
Other sources
Multiple SSRF vulnerabilities exist in the memos API service that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29028?
CVE-2024-29028 is classified as a medium severity SSRF vulnerability.
How do I fix CVE-2024-29028?
To resolve CVE-2024-29028, upgrade to memos version 0.16.1 or later.
What type of vulnerability is CVE-2024-29028?
CVE-2024-29028 is an SSRF (Server-Side Request Forgery) vulnerability.
What impact does CVE-2024-29028 have on security?
CVE-2024-29028 allows unauthenticated users to enumerate the internal network, potentially exposing sensitive information.
In which version was CVE-2024-29028 fixed?
CVE-2024-29028 was fixed in memos version 0.16.1.