CVE-2023-46128
Nautobot vulnerable to exposure of hashed user passwords via REST API
7.7
HIGH
CVSS 3.1
EPSS 0.53%
描述
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3.
如何修補 CVE-2023-46128
要修補 CVE-2023-46128,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.3 或更新版本
- —升級至 1ce8e5c658a075c29554d517cd453675e5d40d71 或更新版本
CVE-2023-46128 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 2.0.0, < 2.0.3
- from 0, < 1ce8e5c658a075c29554d517cd453675e5d40d71 | >= 2.0.0, < 2.0.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.7 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |