|
Message-ID: <4f88c2cf-994b-6a33-66a5-07694d5032c5@census-labs.com>
Date: Fri, 23 Dec 2022 20:42:51 +0200
From: Charalampos Maraziaris <cmaraziaris@...sus-labs.com>
To: oss-security@...ts.openwall.com
Subject: Multiple vulnerabilities in Snipe-IT
Hello all,
I have identified an XSS (CVE-2022-44380) and a user fingerprinting issue (CVE-2022-44381) in Snipe-IT versions prior to 6.0.14.
There's more information about these issues here:
https://census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/
The Snipe-IT project has patched CVE-2022-44380 in version 6.0.14, but CVE-2022-44381 has yet to be addressed correctly.
Best Regards,
Charalampos Maraziaris
Download attachment "OpenPGP_signature" of type "application/pgp-signature" (841 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.