CVE-2022-23064
snipe-IT vulnerable to host header injection
8.8
HIGH
CVSS 3.1
EPSS 0.44%
Description
Snipe-IT is a free, open-source IT asset/license management systemIn Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This can lead to account take over.
How to fix CVE-2022-23064
To remediate CVE-2022-23064, upgrade the affected package to a fixed version below.
- —upgrade to 5.4.0 or later
Is CVE-2022-23064 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.0-alpha, < 5.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |