Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users
Vulnerability Description
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `users.edit` permission to lock every admin out of the instance by editing the `activated` flag (which determines whether or not a user can login) and the `ldap_import` flag, which determines whether or not the user can request a password reset. Version 8.6.0 contains a patch.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
Snipe-IT 安全漏洞
Vulnerability Description
Snipe-IT是Grokability开源的一套开源IT资产/许可证管理系统。 Snipe-IT 8.6.0之前版本存在安全漏洞,该漏洞源于非管理员用户持有users.edit权限时,可编辑activated和ldap_import标志,可能导致锁定所有管理员账户。
CVSS Information
N/A
Vulnerability Type
N/A