Networktocode

Nautobot

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 28.05.2026 17:01:21
  • Zuletzt bearbeitet 29.05.2026 13:29:06

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several...

  • EPSS 0.31%
  • Veröffentlicht 28.05.2026 17:00:06
  • Zuletzt bearbeitet 29.05.2026 13:27:23

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bulk-rename endpoints (for example, /dcim/interfaces/rename/) were vulnerable to application-wide denial of service via maliciously c...

  • EPSS 0.24%
  • Veröffentlicht 28.05.2026 16:59:06
  • Zuletzt bearbeitet 29.05.2026 13:26:24

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP...

  • EPSS 0.28%
  • Veröffentlicht 28.05.2026 16:57:45
  • Zuletzt bearbeitet 28.05.2026 19:30:57

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not inten...

  • EPSS 0.25%
  • Veröffentlicht 31.03.2026 19:27:29
  • Zuletzt bearbeitet 07.04.2026 16:10:20

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creation and editing via the REST API fails to apply the password validation rules defined by Django's AUTH_PASSWORD_VALIDATORS setting (...

  • EPSS 0.38%
  • Veröffentlicht 10.06.2025 15:43:59
  • Zuletzt bearbeitet 21.08.2025 22:34:19

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device,...

  • EPSS 0.3%
  • Veröffentlicht 10.06.2025 15:40:21
  • Zuletzt bearbeitet 21.08.2025 22:36:18

Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insufficient security configuration of the Jinja2 templating feature used in com...

  • EPSS 0.4%
  • Veröffentlicht 28.05.2024 23:15:17
  • Zuletzt bearbeitet 26.08.2025 16:21:03

Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or th...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 14.05.2024 15:39:30
  • Zuletzt bearbeitet 26.08.2025 16:16:00

Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally...

  • EPSS 0.49%
  • Veröffentlicht 01.05.2024 11:15:47
  • Zuletzt bearbeitet 26.08.2025 18:54:06

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query...