Impact
Snipe‑IT before version 8.7.0 does not correctly enforce the viewKeys permission during CSV export and API index operations. An authenticated user who only has licenses.view authority can retrieve all product license keys, effectively bypassing the intended access control. This flaw is classified as CWE‑204, reflecting a failure to properly secure the API and export functionality. The result is unintended disclosure of sensitive license data to users who do not have full read access.
Affected Systems
The vulnerability affects Snipe‑IT software from grokability. All installations running any Snipe‑IT build earlier than 8.7.0 are potentially impacted. No granular version list is provided beyond the stated cutoff, so any deployment dated before 8.7.0 requires attention.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium level of severity. No EPSS data is available, and the issue is not listed in CISA’s KEV catalog. Because the flaw requires authentication with licenses.view permission—a role likely assigned to users who manage licenses—an attacker would need to be a legitimate user or obtain credentials. Once authenticated, the attacker can issue a CSV export or API request and acquire all product keys in bulk. Thus, the exploitability is moderate; the impact is mainly confidentiality loss of license information.
OpenCVE Enrichment