CVE-2022-23064: Snipe-IT - Host Header Injection
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-23064?
CVE-2022-23064 is a vulnerability in Snipe-IT versions v3.0-alpha to v5.3.7 that allows for Host Header Injection.
How does CVE-2022-23064 affect Snipe-IT?
CVE-2022-23064 affects Snipe-IT versions v3.0-alpha to v5.3.7 by allowing an attacker to send password reset links to users that lead to an attacker-controlled server.
What is the severity of CVE-2022-23064?
The severity of CVE-2022-23064 is rated as high with a CVSS score of 8.8.
How can CVE-2022-23064 be fixed?
To fix CVE-2022-23064, upgrade Snipe-IT to a version beyond v5.3.7.
Is there any additional information about CVE-2022-23064?
For more information about CVE-2022-23064, you can refer to the following references: [Link 1](https://github.com/snipe/snipe-it/commit/0c4768fd2a11ac26a61814cef23a71061bfd8bcc), [Link 2](https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-23064)