CVE-2022-1155
Old sessions not blocked by login enable function in Snipe-IT
7.4
HIGH
CVSS 3.1
EPSS 0.98%
描述
Snipe-IT is a FOSS project for asset management in IT Operations. In Snipe-IT versions 5.4.1 and 6.0.0-RC-5 and prior, active sessions are not revoked when a user account is disabled, allowing that user to still access information that they should no longer be able to. Workarounds include using the KillAllSessions console command, clearing the contents of the storage/framework/sessions directory, or changing the cookie name, but all of those options logout ALL users, which could be kind of annoying. This issue is fixed in versions 6.0.0-RC-6 and 5.4.2.
如何修補 CVE-2022-1155
要修補 CVE-2022-1155,請將受影響套件升級到下列已修補版本。
- —升級至 6.0.0-RC-6 或更新版本
CVE-2022-1155 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 6.0.0-RC-1, < 6.0.0-RC-6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |