Auto-merge PR#8713

Auto-merge PR#8713
This commit is contained in:
CVE Team 2023-03-01 20:25:20 -05:00 committed by GitHub
commit 904aa7e1ac
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -3,7 +3,7 @@
"ASSIGNER": "security@huntr.dev",
"ID": "CVE-2022-4803",
"STATE": "PUBLIC",
"TITLE": "Improper Access Control in usememos/memos"
"TITLE": "Authorization Bypass Through User-Controlled Key in usememos/memos"
},
"affects": {
"vendor": {
@ -36,7 +36,7 @@
"description_data": [
{
"lang": "eng",
"value": "Improper Access Control in GitHub repository usememos/memos prior to 0.9.1."
"value": "Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1."
}
]
},
@ -62,7 +62,7 @@
"description": [
{
"lang": "eng",
"value": "CWE-284 Improper Access Control"
"value": "CWE-639 Authorization Bypass Through User-Controlled Key"
}
]
}
@ -86,4 +86,4 @@
"advisory": "0fba72b9-db10-4d9f-a707-2acf2004a286",
"discovery": "EXTERNAL"
}
}
}