PT-2021-23007 · Snipe-It · Snipe-It

Published

2021-12-10

·

Updated

2022-08-09

·

CVE-2021-4089

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions snipe-it versions prior to 5.3.4
Description The issue is related to Improper Access Control. Regular users with DENY set to all models permissions can still view model information via the "/models/{id}/clone" endpoint due to no authorize('view') permission being set.
Recommendations For snipe-it versions prior to 5.3.4, update to version 5.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/models/{id}/clone" endpoint to minimize the risk of exploitation. Additionally, review and adjust the permissions for regular users to ensure they cannot view model information without proper authorization.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-4089
GHSA-9VWF-54M9-GC4F

Affected Products

Snipe-It