GHSA-5wx7-xq8j-v4qm: Medium severity composer/snipe/snipe-it vulnerability
Impact The createdby of an import file can be arbitrarily overwritten via the Importer API endpoint by a user with CSV import capabilities who also has a valid API key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/snipe/snipe-itto a version that resolves this vulnerability.Fixed in 8.6.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs CSV import capabilities and a valid API key. The vulnerability is not described as exploitable by unauthenticated users.
What can an attacker change through exploitation?
They can arbitrarily overwrite the created_by field of an import file through the Importer API endpoint. This affects the integrity of import-file creator attribution.
Does exploitation require user interaction?
Yes. The supplied severity vector indicates that user interaction is required, although the advisory does not specify what form that interaction takes.