CVE-2024-29030: GHSL-2023-154_GHSL-2023-156: Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS) in memos API - CVE-2024-29028, CVE-2024-29029, CVE-2024-29030
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
Other sources
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticated users to enumerate the internal network. Version 0.22.0 of memos removes the vulnerable file.
— GitHub
Multiple SSRF vulnerabilities exist in the memos API service that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.
— GitHub Security Lab
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29030?
CVE-2024-29030 has a medium severity due to its potential for exposing internal network enumeration.
How do I fix CVE-2024-29030?
To fix CVE-2024-29030, upgrade to memos version 0.22.0 or later.
Who is affected by CVE-2024-29030?
Authenticated users of memos version 0.13.2 are affected by CVE-2024-29030.
What does CVE-2024-29030 allow?
CVE-2024-29030 allows authenticated users to perform server-side request forgery leading to internal network enumeration.
When was CVE-2024-29030 disclosed?
CVE-2024-29030 was disclosed in 2024.