Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APPKEY. This is exacerbated by .env files, available from the product's repository, that have default APPKEY values.
{ "nvd_published_at": "2024-10-11T13:15:16Z", "cwe_ids": [ "CWE-1393" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-10-11T17:47:51Z" }