漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Snipe-IT Checkout Request Cancellation IDOR
Vulnerability Description
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Snipe-IT 授权问题漏洞
Vulnerability Description
Snipe-IT是Snipe-IT公司的一款资产管理系统。 Snipe-IT 8.6.0之前版本存在安全漏洞,该漏洞源于cancel_by_admin和requestingUser值从用户控制的URL路径段读取且未进行服务端授权检查,存在不安全的直接对象引用,可能导致低权限用户绕过请求所有权检查,取消其他用户的待处理借出请求,并可通过枚举连续整数标识取消所有待处理请求,破坏资产请求工作流。
CVSS Information
N/A
Vulnerability Type
N/A