Improper Access Control in snipe/snipe-it

Valid

Reported on

Feb 23rd 2022


Description

It was found that if a user is not having access to the requested items module, a normal user with no access can still access and view the requested content.

It is a more detailed explanation of the given report where it was marked as invalid : https://huntr.dev/bounties/783cfb0c-7e4d-4fdd-86c6-bd92743aee41/

Proof of Concept

  1. Create two users, one admin and one normal user(Only give view accessories access to the normal user)
  2. In the screenshot, you can see the normal user is not having access to the requested module.
  3. But with forced browsing, we can clearly see that the normal user can access the requested module.

Screenshots

Accessories view permission to normal user

alt text

alt text

Normal user view requested items

alt text

Impact

This vulnerability will help an attacker view restricted content.

We are processing your report and will contact the snipe/snipe-it team within 24 hours. 2 years ago
shubh123-tri modified the report
2 years ago
shubh123-tri modified the report
2 years ago
We have contacted a member of the snipe/snipe-it team and are waiting to hear back 2 years ago
We have sent a follow up to the snipe/snipe-it team. We will try again in 7 days. 2 years ago
We have sent a second follow up to the snipe/snipe-it team. We will try again in 10 days. 2 years ago
We have sent a third and final follow up to the snipe/snipe-it team. This report is now considered stale. 2 years ago
snipe validated this vulnerability 2 years ago
shubh123-tri has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
snipe marked this as fixed in 5.4.4 with commit 2e9cf8 2 years ago
snipe has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation