CVE-2022-0178: Missing Authorization in snipe/snipe-it
Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
Other sources
Users with no system permissions are able to see and create personal access tokens
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-0178?
CVE-2022-0178 is a missing authorization vulnerability in Snipe Snipe-IT, allowing users with no system permissions to see and create personal access tokens.
How does CVE-2022-0178 affect Snipe Snipe-IT?
CVE-2022-0178 affects Snipe Snipe-IT before version 5.3.8, allowing unauthorized users to see and create personal access tokens.
How severe is CVE-2022-0178?
CVE-2022-0178 has a severity score of 5.4 (medium).
How can I fix CVE-2022-0178 in Snipe Snipe-IT?
To fix CVE-2022-0178, upgrade Snipe Snipe-IT to version 5.3.8 or later.
What are the references for CVE-2022-0178?
The references for CVE-2022-0178 are: [Reference 1](https://github.com/snipe/snipe-it/commit/0e5ef53c352754de2778ffa20c85da15fd6f7ae0), [Reference 2](https://huntr.dev/bounties/81c6b974-d0b3-410b-a902-8324a55b1368), [Reference 3](https://nvd.nist.gov/vuln/detail/CVE-2022-0178).