CVE-2022-0611: Missing Authorization in snipe/snipe-it
Published Feb 15, 2022
·Updated
An unprivileged user of Snipe-IT prior to version 5.3.11 can create maintenance for an asset. Version 5.3.11 contains a patch for this issue.
Other sources
Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
— MITRE
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<5.3.11
5.3.11
Snipeitapp Snipe-it<5.3.11
Remediation
Event History
Feb 15, 2022
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
DescriptionSeverityWeakness
Feb 16, 2022
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 17, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-0611.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.'
3
How can an unprivileged user exploit this vulnerability?
An unprivileged user can create maintenance for an asset on Snipe-IT prior to version 5.3.11.
4
How can this vulnerability be fixed?
To fix this vulnerability, upgrade to version 5.3.11 of Snipe-IT.
5
What is the severity of CVE-2022-0611?
The severity of CVE-2022-0611 is high, with a CVSS score of 8.8.