CVE-2021-4089: Improper Access Control in snipe/snipe-it
Published Dec 10, 2021
·Updated
snipe-it is vulnerable to Improper Access Control
Affected Software
1 affected component
Snipeitapp Snipe-it<=5.3.3
Remediation
Event History
Dec 10, 2021
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-4089?
CVE-2021-4089 is a vulnerability in snipe-it that allows improper access control.
2
How severe is CVE-2021-4089?
CVE-2021-4089 has a severity rating of medium (4.3).
3
What software versions are affected by CVE-2021-4089?
snipe-it versions up to and including 5.3.3 are affected by CVE-2021-4089.
4
How can I fix CVE-2021-4089?
To fix CVE-2021-4089, update snipe-it to a version higher than 5.3.3.
5
Where can I find more information about CVE-2021-4089?
More information about CVE-2021-4089 can be found at the following references: [Github](https://github.com/snipe/snipe-it/commit/1699c09758e56f740437674a8d6ba36443399f24), [Huntr](https://huntr.dev/bounties/19453ef1-4d77-4cff-b7e8-1bc8f3af0862).