PT-2023-7024 · Nautobot · Nautobot

Glennnmatthews

·

Published

2023-10-24

·

Updated

2023-11-01

·

CVE-2023-46128

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nautobot versions 2.0.0 through 2.0.2
Description The issue concerns the exposure of hashed user passwords in Nautobot's REST API endpoints when the ?depth=<N> query parameter is used. This affects any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. Known impacted endpoints include /api/dcim/rack-reservations/, /api/extras/job-results/, /api/extras/notes/, /api/extras/object-changes/, /api/extras/scheduled-jobs/, and /api/users/permissions/, among others, when an appropriate ?depth=<N> query parameter is specified.
Recommendations To resolve the issue, upgrade to Nautobot version 2.0.3 or later. As a temporary workaround, consider restricting access to the impacted REST API endpoints, although this is not recommended as other endpoints may also expose this issue until patched.

Exploit

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-08045
CVE-2023-46128
GHSA-R2HW-74XV-4GQP
PYSEC-2023-220

Affected Products

Nautobot