PT-2023-7024 · Nautobot · Nautobot

Glennnmatthews

·

Publicado

2023-10-24

·

Atualizado

2023-11-01

·

CVE-2023-46128

CVSS v4.0

8.3

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nautobot versions 2.0.0 through 2.0.2
Description The issue concerns the exposure of hashed user passwords in Nautobot's REST API endpoints when the ?depth=<N> query parameter is used. This affects any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. Known impacted endpoints include /api/dcim/rack-reservations/, /api/extras/job-results/, /api/extras/notes/, /api/extras/object-changes/, /api/extras/scheduled-jobs/, and /api/users/permissions/, among others, when an appropriate ?depth=<N> query parameter is specified.
Recommendations To resolve the issue, upgrade to Nautobot version 2.0.3 or later. As a temporary workaround, consider restricting access to the impacted REST API endpoints, although this is not recommended as other endpoints may also expose this issue until patched.

Exploit

Correção

Cleartext Storage of Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08045
CVE-2023-46128
GHSA-R2HW-74XV-4GQP
PYSEC-2023-220

Produtos afetados

Nautobot