Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq28-crg7-95pr

Опубликовано: 08 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Snipe-IT has Privilege Escalation via API Permissions Assignment

Impact

An authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users.

Patches

Patched in https://github.com/grokability/snipe-it/commit/ce18ff669ceb0f0349749fd5d11c1d3d40b10569, fix was released in v8.4.1

Workarounds

None.

Пакеты

Наименование

snipe/snipe-it

composer
Затронутые версииВерсия исправления

< 8.4.1

8.4.1

EPSS

Процентиль: 24%
0.00315
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-281
CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update users. This vulnerability is fixed in 8.4.1.

CVSS3: 8.8
debian
3 месяца назад

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn ...

EPSS

Процентиль: 24%
0.00315
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-281
CWE-863