Impact
The vulnerability lies in the GET /hardware/{asset}/barcode endpoint of snipe‑it, which does not enforce asset view authorization. Authenticated users can supply arbitrary asset identifiers and retrieve barcode images, allowing them to enumerate asset tags and other metadata. The flaw is a missing authorization check (CWE-862) and leads to unauthorized data exposure of asset information, including soft‑deleted and cross‑company assets.
Affected Systems
Affected at the vendor level is snipe‑it from grokability. Any deployment of snipe‑it before version 8.7.0 is vulnerable, regardless of installation size or environment. The specific affected versions are all releases earlier than 8.7.0; the issue is present in each of these releases.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need to be authenticated to use the endpoint, but they can easily iterate asset IDs, making enumeration straightforward once credentials exist. While the vulnerability does not facilitate remote code execution, it permits cross‑tenant data exposure and inventory enumeration, which can aid further attacks.
OpenCVE Enrichment