Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Memos | Usememos | * | 0.9.1 (excluding) |
Attackers at the destination may be able to spoof trusted servers to steal data or cause a denial of service. There are at least two distinct weaknesses that can cause the product to communicate with an unintended destination: