Beveiligingsadvies

CVE-2024-48987

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-10-11 00:00:00
Laatst bijgewerkt 2025-03-25 15:56:20
Toegewezen door mitre
CVSS-score 6.6
Status PUBLISHED

Beschrijving

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.