Impact
Snipe-IT prior to version 8.7.0 fails to enforce access controls for encrypted custom‑field values in asset form templates such as listbox, textarea, markdown‑textarea and date/datetime picker elements. Users who possess any of the assets.edit, assets.checkin, assets.checkout, or assets.audit permissions can open asset forms and read the plaintext encrypted custom‑field data, bypassing the assets.view.encrypted_custom_fields check. This allows confidentiality compromise of sensitive asset information stored in custom fields.
Affected Systems
The vulnerability affects installations of Snipe‑IT by grokability, specifically all releases before 8.7.0. No individual patch level was specified, so any pre‑8.7.0 deployment is susceptible.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a moderate‑severity vulnerability. EPSS data is not available and the issue is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation yet. The exploit requires legitimate authentication with one of the listed permissions, so the attack vector is authenticated; the threat is mainly internal or from a compromised user account. The risk is the accidental or intentional disclosure of confidential asset details to privileged but not explicitly authorized users.
OpenCVE Enrichment