PT-2023-7024 · Nautobot · Nautobot
Glennnmatthews
·
Published
2023-10-24
·
Updated
2023-11-01
·
CVE-2023-46128
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nautobot versions 2.0.0 through 2.0.2
Description
The issue concerns the exposure of hashed user passwords in Nautobot's REST API endpoints when the
?depth=<N> query parameter is used. This affects any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. Known impacted endpoints include /api/dcim/rack-reservations/, /api/extras/job-results/, /api/extras/notes/, /api/extras/object-changes/, /api/extras/scheduled-jobs/, and /api/users/permissions/, among others, when an appropriate ?depth=<N> query parameter is specified.Recommendations
To resolve the issue, upgrade to Nautobot version 2.0.3 or later. As a temporary workaround, consider restricting access to the impacted REST API endpoints, although this is not recommended as other endpoints may also expose this issue until patched.
Exploit
Fix
Cleartext Storage of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nautobot