CVE-2023-46128
Summary
| CVE | CVE-2023-46128 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-25 18:17:00 UTC |
| Updated | 2023-11-01 16:25:00 UTC |
| Description | Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fix `Meta` inheritance in nested serializer classes (#4692) · nautobot/nautobot@1ce8e5c · GitHub |
MISC |
github.com |
|
| Exposure of hashed user passwords via REST API · Advisory · nautobot/nautobot · GitHub |
MISC |
github.com |
|
| Fix `Meta` inheritance in nested serializer classes by glennmatthews · Pull Request #4692 · nautobot/nautobot · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995704 Python (Pip) Security Update for nautobot (GHSA-r2hw-74xv-4gqp)