An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by sett…
高危 CVSS 8.5
摘要
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://gist.github.com/seiyaibuki0523/d8af15eb555808319a2633269a9ebb80
- https://github.com/usememos/memos
- https://gist.github.com/seiyaibuki0523/d8af15eb555808319a2633269a9ebb80
时间线
- nvd_ingest NVD