Impact
Snipe-IT versions up to 8.6.4 fail to enforce the components.view permission when an authenticated user calls GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset and relies on a flag in the response to indicate component view rights, but it does not prevent the returned data from being displayed. Consequently, any user with only assets.view can enumerate component identifiers, names, quantities, and notes, data that would otherwise be protected. This flaw represents a permission bypass that leads to unauthorized disclosure of sensitive inventory information, classified as CWE-862.
Affected Systems
The vulnerability affects the Snipe-IT application, maintained by grokability, at version 8.6.4 and earlier. It was resolved in version 8.7.0. The affected component is the authenticated API endpoint GET /api/v1/hardware/<asset-id>/assigned/components.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity that can compromise confidentiality of component data. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, yet the flaw can be exploited by any authenticated user with assets.view permission. No additional vulnerabilities or prerequisites are required beyond owning an account with limited asset viewing rights, making the attack vector straightforward and potentially impactful to systems that rely on strict access controls.
OpenCVE Enrichment