Medium severity5.3NVD Advisory· Published Dec 25, 2022· Updated Jun 17, 2026
CVE-2022-44381
CVE-2022-44381
Description
Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | <= 6.0.14 | — |
Affected products
3- Snipe-IT/Snipe-ITdescription
Patches
Vulnerability mechanics
References
4- census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-it/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-qqv9-gqh5-7h99ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-44381ghsaADVISORY
- census-labs.com/news/2022/12/23/multiple-vulnerabilities-in-snipe-itghsaWEB
News mentions
0No linked articles in our index yet.