CVE Vulnerabilities

CVE-2022-4847

Incorrectly Specified Destination in a Communication Channel

Published: Dec 29, 2022 | Modified: Jan 05, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

Weakness

The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.

Affected Software

Name Vendor Start Version End Version
Memos Usememos * 0.9.1 (excluding)

Extended Description

Attackers at the destination may be able to spoof trusted servers to steal data or cause a denial of service. There are at least two distinct weaknesses that can cause the product to communicate with an unintended destination:

References