OSV 1.4.0 · github-reviewed · 修改于 2022-08-12 03:17
发布时间
2021-12-16 22:32
GitHub 审查时间
2021-12-15 23:21
NVD 发布时间
2021-12-11 04:15
源文件
advisories/github-reviewed/2021/12/GHSA-9vwf-54m9-gc4f/GHSA-9vwf-54m9-gc4f.json
snipe-it prior to version 5.3.4 is vulnerable to Improper Access Control. Regular users with DENY set to all models permissions can still view model information via the /models/{id}/clone endpoint due to no authorize('view') permission being set.