Improper Access Control in snipe/snipe-it

Valid

Reported on

Feb 23rd 2022


Description

It was found that if a user is not having access to the requested items module, a normal user with no access can still access and view the requested content.

It is a more detailed explanation of the given report where it was marked as invalid : https://huntr.dev/bounties/783cfb0c-7e4d-4fdd-86c6-bd92743aee41/

Proof of Concept

  1. Create two users, one admin and one normal user(Only give view accessories access to the normal user)
  2. In the screenshot, you can see the normal user is not having access to the requested module.
  3. But with forced browsing, we can clearly see that the normal user can access the requested module.

Screenshots

Accessories view permission to normal user

alt text

alt text

Normal user view requested items

alt text

Impact

This vulnerability will help an attacker view restricted content.

We are processing your report and will contact the snipe/snipe-it team within 24 hours. 7 months ago
shubh123-tri modified the report
7 months ago
shubh123-tri modified the report
7 months ago
We have contacted a member of the snipe/snipe-it team and are waiting to hear back 7 months ago
We have sent a follow up to the snipe/snipe-it team. We will try again in 7 days. 7 months ago
We have sent a second follow up to the snipe/snipe-it team. We will try again in 10 days. 7 months ago
We have sent a third and final follow up to the snipe/snipe-it team. This report is now considered stale. 6 months ago
snipe validated this vulnerability 5 months ago
shubh123-tri has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
snipe confirmed that a fix has been merged on 2e9cf8 5 months ago
snipe has been awarded the fix bounty
to join this conversation