CVE-2024-48987
CVE-2024-48987
In short
Snipe-IT versions before 7.0.10 can be taken over by someone who knows the APP_KEY (a secret code), allowing them to run malicious code on the server. The problem is worse because default APP_KEY values are publicly visible in the project's files.
Technical detail
Remote code execution via unsafe cookie deserialization in Snipe-IT before 7.0.10 when the APP_KEY is known or set to a default value exposed in repository .env files. An attacker can craft a malicious serialized payload in cookies to achieve code execution with application privileges.
Summary generated and translated by AI from the official description.
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →