Impact
Snipe‑IT versions prior to 8.7.0 contain a logic flaw in the file deletion handlers where the return status of the underlying storage deletion operation is ignored. The weakness involves ignoring the return value of a storage deletion call (CWE‑212). As a result, deletion requests return a success response even when the physical file remains on the server’s filesystem. Administrators observing the API or UI believe the attachment has been removed, yet the file is still stored and can be accessed by anyone with direct filesystem or backup access.
Affected Systems
Vendors: grokability:snipe‑it. Product: Snipe‑IT web asset management system. Affected releases: all versions earlier than 8.7.0. No specific sub‑versions are excluded; all builds in that range are impacted. The flaw is present in both the web controller and the API controller for uploaded files.
Risk and Exploitability
The flaw carries a CVSS score of 5.1, indicating moderate risk. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is inferred to be through an authenticated administrator or an actor who can trigger the deletion endpoint. Successful exploitation does not provide remote code execution but allows residual data to persist, potentially exposing confidential attachments if filesystem or backup credentials are compromised.
OpenCVE Enrichment