[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-29199Date: (C)2024-03-26   (M)2024-03-27


Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthenticated user unless the Nautobot configuration variable EXEMPT_VIEW_PERMISSIONS is changed from its default value (an empty list) to permit access to specific data by unauthenticated users. This vulnerability is fixed in 1.6.16 and 2.1.9.

Reference:
https://github.com/nautobot/nautobot/commit/2fd95c365f8477b26e06d60b999ddd36882d5750
https://github.com/nautobot/nautobot/commit/dd623e6c3307f48b6357fcc91925bcad5192abfb
https://github.com/nautobot/nautobot/pull/5464
https://github.com/nautobot/nautobot/pull/5465
https://github.com/nautobot/nautobot/releases/tag/v1.6.16
https://github.com/nautobot/nautobot/releases/tag/v2.1.9
https://github.com/nautobot/nautobot/security/advisories/GHSA-m732-wvh2-7cq4

© SecPod Technologies