Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-1923 Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
Github GHSA Github GHSA GHSA-544r-fc65-v832 Snipe-IT allows users to promote or demote themselves or other users
Fixes

Solution

Update to version v6.4.2 to mitigate the issue.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmarx

Published:

Updated: 2024-08-01T21:18:06.834Z

Reserved: 2024-06-06T14:26:24.960Z

Link: CVE-2024-5685

cve-icon Vulnrichment

Updated: 2024-07-12T19:08:38.357Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-14T10:15:10.817

Modified: 2024-11-21T09:48:09.570

Link: CVE-2024-5685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.