Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
{
"cwe_ids": [
"CWE-1393"
],
"github_reviewed": true,
"github_reviewed_at": "2024-10-11T17:47:51Z",
"nvd_published_at": "2024-10-11T13:15:16Z",
"severity": "HIGH"
}