golang / vulndb

[mirror] The Go Vulnerability Database
Other
562 stars 61 forks source link

x/vulndb: potential Go vuln in github.com/usememos/memos: GHSA-w57v-6xp4-rm2v #1191

Closed GoVulnBot closed 1 year ago

GoVulnBot commented 1 year ago

In GitHub Security Advisory GHSA-w57v-6xp4-rm2v, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/usememos/memos 0.9.0 < 0.9.0

Cross references: No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: TODO
    versions:
      - fixed: 0.9.0
    packages:
      - package: github.com/usememos/memos
description: usememos/memos is an open-source, self-hosted memo hub with knowledge
    management and socialization. Versions prior to 0.9.0 improperly maintain access
    control allowing an attacker to take over an account by changing header values
    in the HTTP request.
cves:
  - CVE-2022-4689
ghsas:
  - GHSA-w57v-6xp4-rm2v
zpavlinovic commented 1 year ago

Binary where packages with fix are not imported by anyone.

tatianab commented 1 year ago

Needs excluded report

gopherbot commented 1 year ago

Change https://go.dev/cl/513918 mentions this issue: data/excluded: batch add 26 excluded reports

gopherbot commented 5 months ago

Change https://go.dev/cl/592835 mentions this issue: data/reports: unexclude 50 reports

gopherbot commented 2 months ago

Change https://go.dev/cl/607232 mentions this issue: data/reports: unexclude 20 reports (30)