CVE-2023-46128

Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-25 18:17

Updated : 2023-11-01 16:25


NVD link : CVE-2023-46128

Mitre link : CVE-2023-46128

CVE.ORG link : CVE-2023-46128


JSON object : View

Products Affected

networktocode

  • nautobot
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor