Headline
GHSA-j2gj-g3p9-7mrr: Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. As of commit c9aa2eeb9
access tokens which fail validation are rejected.
Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos
Critical severity GitHub Reviewed Published Sep 1, 2023 to the GitHub Advisory Database • Updated Sep 1, 2023
Related news
CVE-2023-4696: huntr – Security Bounties for any GitHub repository
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.