cve/2024/CVE-2024-29028.md
2024-06-18 02:51:15 +02:00

848 B

CVE-2024-29028

Description

memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vulnerability is fixed in 0.16.1.

POC

Reference

Github

No PoCs found on GitHub currently.