v5.3.10

grokability/snipe-itv5.3.10Feb 13, 2022by snipe

AI Summary

A small security release addressing possible email address enumeration via forgotten password responses and an unauthorized supplier view issue.

Key Highlights

  • Security fix for email address enumeration via forgotten password response text.
  • Security fix for unauthorized supplier view.
  • Warning regarding the upcoming PHP 7.4 requirement.

Full Release Notes

### ⚠️  IMPORTANT: Later versions of Snipe-IT will require PHP 7.4 or greater. It is highly recommended you upgrade your version of PHP NOW. 

(This is a requirement in order for us to be able to pull forward the dependencies that will allow us to support PHP8 and beyond moving forward.)

This is a small security release that addresses possible enumeration through email addresses via the forgotten password response text, and an un-gated supplier view for an authenticated but unauthorized Snipe-IT user.

For a full list of changes, [see the complete changelog](https://github.com/snipe/snipe-it/compare/v5.3.9...v5.3.10).

### Upgrading

For general upgrading instructions, [click here](https://snipe-it.readme.io/docs/upgrading). Users who installed Snipe-IT via Git (recommended) can just run `php upgrade.php`.