CVE-2022-0569: Observable Discrepancy in snipe/snipe-it
Published Feb 12, 2022
·Updated
Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
Other sources
Snipe-IT prior to v5.3.10 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<5.3.10
5.3.10
Snipeitapp Snipe-it<5.3.9
Remediation
Event History
Feb 12, 2022
CVE Published
via MITRE·11:55 PM
Data Sourced
via MITRE·11:55 PM
DescriptionSeverityWeakness
Feb 14, 2022
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 15, 2022
Advisory Published
12:02 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-0569?
The severity of CVE-2022-0569 is medium with a CVSS score of 4.3.
2
How does CVE-2022-0569 affect Snipe-IT?
CVE-2022-0569 affects Snipe-IT versions prior to v5.3.10 by exposing sensitive information to an unauthorized actor.
3
How can I fix CVE-2022-0569?
To fix CVE-2022-0569, update Snipe-IT to version v5.3.10 or later.
4
What is the CWE of CVE-2022-0569?
The CWE of CVE-2022-0569 is CWE-200 (Information Exposure) and CWE-203 (Information Exposure Through API).
5
Where can I find more information about CVE-2022-0569?
You can find more information about CVE-2022-0569 on the NIST NVD website or the GitHub and Huntr.dev links provided.