Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-24T14:17:52.830Z
Updated: 2024-09-11T17:02:05.910Z
Reserved: 2023-10-16T17:51:35.572Z
Link: CVE-2023-46128
Vulnrichment
Updated: 2024-08-02T20:37:39.490Z
NVD
Status : Modified
Published: 2023-10-25T18:17:36.607
Modified: 2024-11-21T08:27:56.323
Link: CVE-2023-46128
Redhat
No data.