PT-2021-23007 · Snipe-It · Snipe-It
Published
2021-12-10
·
Updated
2022-08-09
·
CVE-2021-4089
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
snipe-it versions prior to 5.3.4
Description
The issue is related to Improper Access Control. Regular users with
DENY set to all models permissions can still view model information via the "/models/{id}/clone" endpoint due to no authorize('view') permission being set.Recommendations
For snipe-it versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/models/{id}/clone" endpoint to minimize the risk of exploitation. Additionally, review and adjust the permissions for regular users to ensure they cannot view model information without proper authorization.
Exploit
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snipe-It