logo

CVE-2022-23064 snipe/snipe-it

Package

Manager: composer
Name: snipe/snipe-it
Vulnerable Version: >=3.0-alpha <5.4.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00396 pctl0.59669

Details

snipe-IT vulnerable to host header injection Snipe-IT is a free, open-source IT asset/license management systemIn Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This can lead to account take over.

Metadata

Created: 2022-05-03T00:00:43Z
Modified: 2022-05-03T06:29:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9vh6-qfv6-vcqp/GHSA-9vh6-qfv6-vcqp.json
CWE IDs: ["CWE-74"]
Alternative ID: GHSA-9vh6-qfv6-vcqp
Finding: F184
Auto approve: 1