-
Notifications
You must be signed in to change notification settings - Fork 74
Closed
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
Description
In GitHub Security Advisory GHSA-qrrf-xvcf-p64q, there is a vulnerability in the following Go packages or modules:
| Unit | Fixed | Vulnerable Ranges |
|---|---|---|
| github.com/usememos/memos | <= 0.9.0 |
Cross references:
No existing reports found with this module or alias.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: TODO
versions:
- {}
packages:
- package: github.com/usememos/memos
description: In usememos/memos 0.9.0 and prior, an attacker can delete other users'
posts via post id, which can be done via brute force.
cves:
- CVE-2022-4797
ghsas:
- GHSA-qrrf-xvcf-p64q
Metadata
Metadata
Assignees
Labels
excluded: EFFECTIVELY_PRIVATEThis vulnerability exists in a package can be imported, but isn't meant to be outside that module.This vulnerability exists in a package can be imported, but isn't meant to be outside that module.