Impact
Snipe‑IT 8.5.0 through 8.6.3 contains an open redirect in the SAML assertion‑consumer endpoint. The vulnerability allows an attacker to embed an arbitrary absolute URL in the RelayState parameter, which is then passed unchanged to the HTTP Location header after successful authentication. Because no account or IdP compromise is required, this flaw can be exploited by an unauthenticated attacker who supplies a crafted IdP‑initiated SSO link to a victim. The resulting redirect can lead the victim to phishing sites designed to harvest credentials.
Affected Systems
The flaw affects Snipe‑IT instances that have SAML SSO enabled. The affected range is version 8.5.0 through 8.6.3. Higher‑level vendor is Grokability. The patch is available in 8.7.0 (commit d30b73d).
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attack execution requires only an SSO link with a crafted RelayState; it does not require prior authentication or IdP compromise, so the likelihood of attack is high for exposed SAML SSO endpoints.
OpenCVE Enrichment