CVE-2024-29199
- EPSS 0.63%
- Veröffentlicht 26.03.2024 03:15:13
- Zuletzt bearbeitet 26.08.2025 17:18:09
Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthent...
CVE-2024-23345
- EPSS 0.43%
- Veröffentlicht 23.01.2024 00:15:26
- Zuletzt bearbeitet 21.11.2024 08:57:33
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input s...
CVE-2023-51649
- EPSS 0.45%
- Veröffentlicht 22.12.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:38:32
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level `extras.run_job...
CVE-2023-50263
- EPSS 0.75%
- Veröffentlicht 12.12.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:36:46
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs `/files/get/?name=...`...
CVE-2023-48705
- EPSS 0.54%
- Veröffentlicht 22.11.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:32:17
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot versions earlier than 1.6.6 or 2.0.5 are potentially affected by a cross-site scripting vulnerability. Due to incorrect usage of Dj...
CVE-2023-46128
- EPSS 0.53%
- Veröffentlicht 25.10.2023 18:17:36
- Zuletzt bearbeitet 21.11.2024 08:27:56
Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose...
CVE-2023-25657
- EPSS 1.53%
- Veröffentlicht 21.02.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:53
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions earlier than 1.5.7 are impacted by a remote code execution vulnerability. Nautobot did not properly sandbox Jinja2 template rendering. In Nautobot 1...