CVE-2024-48987: High severity snipe-it vulnerability
Published Oct 11, 2024
·Updated
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APPKEY. This is exacerbated by .env files, available from the product's repository, that have default APPKEY values.
Affected Software
2 affected componentsFixes available
composer/snipe/snipe-it<7.0.10
7.0.10
Snipeitapp Snipe-it<7.0.10
Event History
Oct 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
Affected Software
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-48987?
CVE-2024-48987 has a critical severity level due to its potential for remote code execution.
2
How do I fix CVE-2024-48987?
To fix CVE-2024-48987, upgrade Snipe-IT to version 7.0.10 or later.
3
What causes CVE-2024-48987?
CVE-2024-48987 is caused by insufficient validation of cookie serialization linked with the APP_KEY.
4
Who is affected by CVE-2024-48987?
CVE-2024-48987 affects all Snipe-IT instances before version 7.0.10 that have a known APP_KEY.
5
Is there a workaround for CVE-2024-48987?
The only effective workaround for CVE-2024-48987 is to update to the latest version of Snipe-IT.