CVE-2024-5685: Broken Function Level Authorization (BFLA) in snipe/snipe-it
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 6.4.2 - Upgrade
Upgrade
snipe/snipe-itto a version that resolves this vulnerability.Fixed in v6.4.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5685?
CVE-2024-5685 is classified as a medium severity vulnerability due to the potential for unauthorized user privilege escalation.
How do I fix CVE-2024-5685?
To fix CVE-2024-5685, you should upgrade your Snipe-IT installation to version 6.4.2 or later.
Who is affected by CVE-2024-5685?
CVE-2024-5685 affects Snipe-IT versions from 4.6.17 to 6.4.1 that have users with 'User:edit' and 'Self:api' permissions.
What are the consequences of CVE-2024-5685?
CVE-2024-5685 allows users with certain permissions to promote or demote themselves or others, resulting in unauthorized access to user roles.
When was CVE-2024-5685 published?
CVE-2024-5685 was published and reported in the context of Snipe-IT vulnerability management practices.