CVE-2022-0579: Missing Authorization in snipe/snipe-it
Published Feb 14, 2022
·Updated
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
Other sources
Snipe-IT prior to 5.3.9 is vulnerable to improper privilege management. A user who does not have access to the supplier module may view supplier content.
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<5.3.9
5.3.9
Snipeitapp Snipe-it<5.3.9
Remediation
Event History
Feb 14, 2022
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 15, 2022
Advisory Published
12:02 AM
Frequently Asked Questions
1
What is CVE-2022-0579?
CVE-2022-0579 is a vulnerability in the Packagist snipe/snipe-it software.
2
What is the severity of CVE-2022-0579?
CVE-2022-0579 has a severity rating of 6.5 (Medium).
3
How does CVE-2022-0579 affect Snipe-IT?
CVE-2022-0579 allows users without access to the supplier module to view supplier content in Snipe-IT prior to version 5.3.9.
4
How can I check if I am affected by CVE-2022-0579?
If you are using Snipe-IT prior to version 5.3.9, you may be affected by CVE-2022-0579.
5
How do I fix CVE-2022-0579?
To fix CVE-2022-0579, you need to update Snipe-IT to version 5.3.9 or later.