
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-4804 is an Improper Authorization vulnerability discovered in GitHub repository usememos/memos versions prior to 0.9.1. The vulnerability was disclosed on December 28, 2022 (NVD).
The vulnerability has a CVSS v3.1 Base Score of 5.3 (Medium) with the following metrics: Attack Vector: Network, Attack Complexity: Low, Privileges Required: None, User Interaction: None, Scope: Unchanged, Confidentiality: Low, Integrity: None, Availability: None (AttackerKB).
The vulnerability could allow unauthorized access to information, as indicated by the CVSS metrics showing a Low impact on Confidentiality while maintaining no impact on Integrity and Availability (AttackerKB).
The vulnerability has been fixed in version 0.9.1 of the usememos/memos repository. Users should upgrade to this version or later to mitigate the vulnerability (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."