Impact
The vulnerability resides in the ExternalUrl validation rule of snipe‑it, enabling an SSRF flaw when the rule fails to detect IPv6 transition addresses that encode private IPv4 targets. An attacker with super‑admin rights can set webhook URLs that use NAT64, 6to4 or Teredo transition addresses, forcing the application to request internal or cloud metadata services. This provides unauthorized access to internal resources and sensitive configuration data, compromising confidentiality and potentially integrity of systems exposed behind the internal network.
Affected Systems
The issue affects all installations of the snipe‑it application provided by grokability that run any version prior to 8.7.0. No specific patch version list is supplied beyond the cutoff, so any deployment below that version is vulnerable.
Risk and Exploitability
The CVSS score of 5.9 denotes a medium severity, and the exploit is not currently listed in CISA KEV. The EPSS score is not available, so the probability of exploitation cannot be quantified, but the requirement for super‑admin privileges limits the threat to environments where privilege escalation is feasible. Attackers can reach internal endpoints by simply configuring bot URLs, bypassing normal SSRF defenses, making the vulnerability actionable after privilege gain.
OpenCVE Enrichment