blob: 61728ced4cfdc0ef7021d382281881052586ce13 [file] [log] [blame]
id: GO-2023-2038
modules:
- module: github.com/usememos/memos
versions:
- fixed: 0.13.2
vulnerable_at: 0.13.1
summary: Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos in github.com/usememos/memos
cves:
- CVE-2023-4696
ghsas:
- GHSA-j2gj-g3p9-7mrr
references:
- advisory: https://github.com/advisories/GHSA-j2gj-g3p9-7mrr
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-4696
- fix: https://github.com/usememos/memos/commit/c9aa2eeb9852047e4f41915eb30726bd25f07ecd
- web: https://huntr.dev/bounties/4747a485-77c3-4bb5-aab0-21253ef303ca
source:
id: GHSA-j2gj-g3p9-7mrr
created: 2024-08-20T12:01:50.2721-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE