Опубликовано: 14 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1
Описание
Snipe-IT allows users to promote or demote themselves or other users
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-5685
- https://github.com/snipe/snipe-it/pull/14745
- https://github.com/snipe/snipe-it/commit/34f1ea1c0ecd403047cd1327569ee391a7201cc1
- https://advisory.checkmarx.net/?search=CVE-2024-5685
- https://devhub.checkmarx.com/cve-details/CVE-2024-5685
- https://github.com/snipe/snipe-it/releases/tag/v6.4.2
Пакеты
Наименование
snipe/snipe-it
composer
Затронутые версииВерсия исправления
< 6.4.2
6.4.2
Связанные уязвимости
CVSS3: 7.6
nvd
больше 1 года назад
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
CVSS3: 7.6
debian
больше 1 года назад
Users with "User:edit" and "Self:api" permissionscan promote or demote ...