GHSA-636j-7x7r-gvw2

    Dashboard / Vulnerabilities / GHSA-636j-7x7r-gvw2

    GHSA-636j-7x7r-gvw2

    Published: 31 Mar 2022Last Modified: 8 Nov 2023
    Aliases:

    Summary: Old sessions not blocked by login enable function in Snipe-IT

    Details: Snipe-IT is a FOSS project for asset management in IT Operations. In Snipe-IT versions 5.4.1 and 6.0.0-RC-5 and prior, active sessions are not revoked when a user account is disabled, allowing that user to still access information that they should no longer be able to. Workarounds include using the KillAllSessions console command, clearing the contents of the storage/framework/sessions directory, or changing the cookie name, but all of those options logout ALL users, which could be kind of annoying. This issue is fixed in versions 6.0.0-RC-6 and 5.4.2.

    Affected packages

    Package

    Name: snipe/snipe-it

    Purl: pkg:composer/snipe/snipe-it

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 6.0.0-RC-1
    Fixed -6.0.0-RC-6

    Affected versions

    v6.0.0-RC-1
    v6.0.0-RC-2
    v6.0.0-RC-3
    v6.0.0-RC-4
    v6.0.0-RC-5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-636j-7x7r-gvw2 | CVE-DB