CVE-2022-4806

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
usememosmemos
𝑥
< 0.9.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gdb
suse enterprise desktop 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise desktop 15 SP7
14.2-150400.15.23.1
fixed
suse enterprise sap 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise sap 15 SP7
14.2-150400.15.23.1
fixed
suse enterprise server 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise server 15 SP7
14.2-150400.15.23.1
fixed
gdbserver
suse enterprise desktop 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise desktop 15 SP7
14.2-150400.15.23.1
fixed
suse enterprise sap 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise sap 15 SP7
14.2-150400.15.23.1
fixed
suse enterprise server 15 SP6
13.2-150400.15.14.1
fixed
suse enterprise server 15 SP7
14.2-150400.15.23.1
fixed