CVE-2022-1155: Old sessions are not blocked by the login enable function. in snipe/snipe-it
Published Mar 30, 2022
·Updated
Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
Affected Software
2 affected components
Snipeitapp Snipe-it<5.3.10
Snipeitapp Snipe-it=5.3.10
Remediation
Event History
Mar 30, 2022
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-1155.
2
What is the severity of CVE-2022-1155?
The severity of CVE-2022-1155 is high, with a severity value of 7.4.
3
What is the affected software?
The affected software is Snipeitapp Snipe-it prior to version 5.3.10.
4
How can I fix CVE-2022-1155?
To fix CVE-2022-1155, update your snipe/snipe-it GitHub repository to version 5.3.10 or later.
5
Where can I find more information about CVE-2022-1155?
You can find more information about CVE-2022-1155 at the following references: [Link to GitHub commit](https://github.com/snipe/snipe-it/commit/bdabbbd4e98e88ee01e728ceb4fd512661fbd38d) and [Link to huntr.dev](https://huntr.dev/bounties/ebc26354-2414-4f72-88aa-f044aec2b2e1).