EN

high

Snipe-IT: Bypassing security controls possible

CERT-Bund (BSI) reports one vulnerability in Snipe-IT with severity high. The stated impact is bypassing security controls. The full description, affected versions and recommended action are available from CERT-Bund (BSI).

Attack vector
over the network
Access needed
yes, an account is needed

What this means for you

A protective measure can be bypassed — login, permission checks or filters do not work as intended. Check whether the system is reachable from the internet; if so, the update takes precedence.

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.