Description
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to version v6.4.2 to mitigate the issue.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1923 | Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1. |
Github GHSA |
GHSA-544r-fc65-v832 | Snipe-IT allows users to promote or demote themselves or other users |
References
History
No history.
Status: PUBLISHED
Assigner: Checkmarx
Published:
Updated: 2024-08-01T21:18:06.834Z
Reserved: 2024-06-06T14:26:24.960Z
Link: CVE-2024-5685
Updated: 2024-07-12T19:08:38.357Z
Status : Awaiting Analysis
Published: 2024-06-14T10:15:10.817
Modified: 2024-11-21T09:48:09.570
Link: CVE-2024-5685
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA