Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-29028

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.1%
CVSS Severity
CVSS v3 Score 5.8
Products affected by CVE-2024-29028
  • Usememos » Memos » Version: 0.13.2
    cpe:2.3:a:usememos:memos:0.13.2
  • Usememos » Memos » Version: 0.14.0
    cpe:2.3:a:usememos:memos:0.14.0
  • Usememos » Memos » Version: 0.14.1
    cpe:2.3:a:usememos:memos:0.14.1
  • Usememos » Memos » Version: 0.14.2
    cpe:2.3:a:usememos:memos:0.14.2
  • Usememos » Memos » Version: 0.14.3
    cpe:2.3:a:usememos:memos:0.14.3
  • Usememos » Memos » Version: 0.14.4
    cpe:2.3:a:usememos:memos:0.14.4
  • Usememos » Memos » Version: 0.15.1
    cpe:2.3:a:usememos:memos:0.15.1
  • Usememos » Memos » Version: 0.15.2
    cpe:2.3:a:usememos:memos:0.15.2
  • Usememos » Memos » Version: 0.16.0
    cpe:2.3:a:usememos:memos:0.16.0


Contact Us

Shodan ® - All rights reserved