Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-j2gj-g3p9-7mrr: Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. As of commit c9aa2eeb9 access tokens which fail validation are rejected.

ghsa
#git

Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos

Critical severity GitHub Reviewed Published Sep 1, 2023 to the GitHub Advisory Database • Updated Sep 1, 2023

Related news

CVE-2023-4696: huntr – Security Bounties for any GitHub repository

Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.