Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Link | Tags |
---|---|
https://github.com/usememos/memos/commit/3556ae4e651d9443dc3bb8a170dd3cc726517a53 | third party advisory patch |
https://huntr.dev/bounties/a24b45d8-554b-4131-8ce1-f33bf8cdbacc | patch third party advisory exploit |