CyberRota Analysis
AI-GeneratedSnipe-IT versions prior to 8.6.1 are vulnerable due to inadequate authorization in the S3 signature image retrieval process, allowing authenticated users to generate a temporary signed URL for any signature filename. This could lead to unauthorized access to sensitive images stored in S3, potentially exposing confidential data. Organizations using Snipe-IT should prioritize upgrading to version 8.6.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks authorization before temporary URL. On S3-backed deployments, authenticated users who know a signature filename can obtain a 5-minute signed S3 URL because the S3 branch returns before the `authorize()` call used by the local-file branch. Version 8.6.1 contains a patch.
Related CVEs
Other vulnerabilities affecting the same vendor(s)