snipe/snipe-it

Licenses: AGPL-3.0 | MIT

Direct Vulnerabilities

Known vulnerabilities in the snipe/snipe-it package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Incorrect Authorization

<8.6.3
  • H
Authorization Bypass Through User-Controlled Key

<8.6.3
  • M
Missing Authorization

<8.6.3
  • M
Cross-site Scripting (XSS)

<8.6.2
  • H
Cross-site Scripting (XSS)

<8.7.0
  • H
Authentication Bypass Using an Alternate Path or Channel

<8.7.0
  • H
Cross-site Scripting (XSS)

<8.7.0
  • H
Missing Authorization

<8.7.0
  • H
Missing Authorization

<8.7.0
  • H
Missing Authorization

<8.7.0
  • H
Incorrect Authorization

<8.7.0
  • H
Information Exposure

<8.7.0
  • H
Incorrect Authorization

<8.7.0
  • H
Missing Authorization

<8.7.0
  • M
Incorrect Authorization

>=4.2.0, <8.7.0
  • H
Race Condition

<8.7.0
  • M
Access Control Bypass

<8.7.0
  • M
Cross-site Scripting (XSS)

<8.7.0
  • H
Improper Handling of Case Sensitivity

<8.7.0
  • H
Improper Privilege Management

<8.7.0
  • M
Improper Cleanup on Thrown Exception

<8.7.0
  • M
Incorrect Authorization

<8.7.0
  • M
Improper Ownership Management

<8.7.0
  • M
Incorrect Authorization

>=8.2.0, <8.7.0
  • H
Missing Authorization

<8.7.0
  • M
Improper Input Validation

<8.7.0
  • M
Information Exposure

<8.7.0
  • M
Authorization Bypass Through User-Controlled Key

<8.7.0
  • M
Incorrect Authorization

<8.7.0
  • M
Incorrect Authorization

<8.7.0
  • M
Improper Removal of Sensitive Information Before Storage or Transfer

<8.7.0
  • L
Race Condition

<8.7.0
  • M
Authorization Bypass Through User-Controlled Key

<8.7.0
  • M
Incorrect Authorization

<8.7.0
  • H
Authorization Bypass Through User-Controlled Key

<8.6.2
  • H
Authorization Bypass Through User-Controlled Key

<8.6.3
  • H
Denial of Service (DoS)

<8.7.1
  • C
Cross-site Scripting (XSS)

<8.7.0
  • M
Missing Authorization

<8.7.0
  • M
Server-side Request Forgery (SSRF)

<8.7.0
  • H
Command Injection

<8.7.0
  • M
Incorrect Calculation

<8.7.0
  • M
Authorization Bypass Through User-Controlled Key

>=7.0.12, <8.7.0
  • H
External Control of File Name or Path

<8.7.0
  • H
Unchecked Return Value

<8.7.0
  • M
Open Redirect

>=8.5.0, <8.7.0
  • H
External Control of File Name or Path

<8.7.0
  • H
Server-side Request Forgery (SSRF)

<8.7.0
  • M
CSV Injection

<8.7.0
  • M
Incorrect Authorization

<8.7.0
  • M
CSV Injection

<8.7.0
  • L
Unchecked Return Value

<8.7.0
  • M
Incorrect Authorization

<8.7.2
  • M
Open Redirect

<8.6.2
  • M
Cross-site Scripting (XSS)

<8.6.2
  • M
Incorrect Authorization

<8.6.1
  • M
Incorrect Authorization

<8.6.2
  • H
Incorrect Authorization

<8.6.2
  • M
Missing Authorization

<8.6.0
  • H
Directory Traversal

<8.6.2
  • M
CSV Injection

<8.5.0
  • M
Authorization Bypass Through User-Controlled Key

<8.6.2
  • M
Cross-site Scripting (XSS)

<8.6.2
  • M
Incorrect Authorization

<8.6.2
  • M
Cross-site Scripting (XSS)

<8.6.2
  • M
Incorrect Authorization

<8.6.2
  • H
Authorization Bypass Through User-Controlled Key

<8.6.2
  • M
Authorization Bypass Through User-Controlled Key

<8.6.2
  • H
Improper Privilege Management

<8.6.0
  • H
Relative Path Traversal

<8.5.0
  • H
Missing Authorization

<8.6.0
  • M
Missing Authorization

<8.5.1
  • M
Improper Authorization

<8.4.1
  • M
Missing Authorization

<8.5.0
  • H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

<8.6.2
  • M
Authorization Bypass Through User-Controlled Key

<8.4.2
  • H
Incorrect Authorization

<8.6.0
  • H
Missing Authorization

<8.5.1
  • M
Allocation of Resources Without Limits or Throttling

<8.6.0
  • H
Incorrect Authorization

<8.6.0
  • H
Missing Authorization

<8.6.0
  • L
Open Redirect

<8.4.1
  • C
Access Control Bypass

<8.4.1
  • H
Incorrect Authorization

<8.4.1
  • L
Cross-site Scripting (XSS)

<8.4.1
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<8.3.7
  • M
Cross-site Scripting (XSS)

<8.3.4
  • M
Arbitrary File Upload

<8.3.3
  • H
Deserialization of Untrusted Data

<8.1.18
  • M
Cross-site Scripting (XSS)

<8.1.18
  • M
Direct Request ('Forced Browsing')

<8.1.0
  • M
Cross-site Scripting (XSS)

>0.0.0
  • M
CSV Injection

>=0.0.0
  • H
Remote Code Execution (RCE)

<7.0.10
  • H
Missing Authorization

<6.4.2
  • M
Cross-site Request Forgery (CSRF)

<6.2.3
  • M
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

<6.2.2
  • M
Cross-site Scripting (XSS)

<6.0.14
  • M
Improper Access Control

<6.0.14
  • M
Access Restriction Bypass

<6.0.11
  • L
Cross-site Scripting (XSS)

<6.0.11
  • M
Session Fixation

<6.0.10
  • M
Arbitrary File Upload

<6.3.2
  • M
Arbitrary File Upload

>=0.0.0
  • M
Information Exposure

>=0.3.0-alpha, <5.3.8
  • M
Access Restriction Bypass

<5.4.4
  • C
Cross-site Scripting (XSS)

<5.4.4
  • H
Cross-site Scripting (XSS)

<5.4.3
  • H
Business Logic Errors

<5.4.2
  • M
Information Exposure

<5.4.0
  • M
Improper Privilege Management

<5.4.0
  • M
Access Restriction Bypass

<5.3.10
  • M
Information Exposure

<5.3.10
  • M
Improper Access Control

<6.0.0-RC-1
  • M
Improper Access Control

<5.3.7
  • M
Cross-site Request Forgery (CSRF)

>=0.0.0, <v5.3.6
  • M
Cross-site Scripting (XSS)

<5.3.5
  • M
Access Restriction Bypass

>=0.0.0, <v5.3.4
  • L
Server-side Request Forgery (SSRF)

<6.0.0-RC-1
  • M
Cross-site Scripting (XSS)

<5.3.3
  • M
Cross-site Scripting (XSS)

<5.3.2
  • L
Cross-site Scripting (XSS)

>=0.0.0, <v5.3.2
  • M
Cross-site Request Forgery (CSRF)

>=0.0.0, <v5.3.2
  • M
Cross-site Request Forgery (CSRF)

<5.3.0
  • M
Cross-site Scripting (XSS)

<5.3.0
  • M
Cross-site Scripting (XSS)

<5.3.0
  • M
Cross-site Scripting (XSS)

<4.6.14