Vulnerabilities
Last updated 43 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs | Medium Risk 6.4 | 8 days ago | 2 hours ago |
|
|
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages | High Risk 7.5 | 2 years ago | 21 days ago |
|
|
nautobot has reflected Cross-site Scripting potential in all object list views | High Risk 7.5 | 2 years ago | 21 days ago |
|
|
Unauthenticated views may expose information to anonymous users | Low Risk 3.7 | 2 years ago | 21 days ago |
|
|
XSS potential in rendered Markdown fields (comments, description, notes, etc.) | High Risk 7.1 | 2 years ago | 21 days ago |
|
|
Unauthenticated db-file-storage views | Low Risk 3.7 | 2 years ago | 21 days ago |
|
|
Clear Text Credentials Exposed via Onboarding Task | Medium Risk 5.7 | 2 years ago | 21 days ago |
|
|
Nautobot vulnerable to exposure of hashed user passwords via REST API | High Risk 7.7 | 2 years ago | 21 days ago |
|
|
Nautobot: Management of users via REST API does not apply configured password validators | Low Risk 2.7 | 6 months ago | 2 months ago |
|
|
Nautobot: GitRepository.current_head field should not be writable through REST API | High Risk 7.1 | 4 months ago | 2 months ago |
|
|
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) | High Risk 8.5 | 4 months ago | 2 months ago |
|
|
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) | Medium Risk 6.5 | 4 months ago | 2 months ago |
|
|
No summary available | Medium Risk 4.3 | 6 months ago | 2 months ago |
|
|
No summary available | Medium Risk 5.4 | 4 months ago | 2 months ago |
|
|
No summary available | Medium Risk 6.5 | 4 months ago | 2 months ago |
|
|
No summary available | High Risk 8.5 | 4 months ago | 2 months ago |
|
|
No summary available | High Risk 7.1 | 4 months ago | 2 months ago |
|
|
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL | Medium Risk 5.3 | 11 months ago | 2 months ago |
|
|
Nautobot may allows uploaded media files to be accessible without authentication | Medium Risk 6.0 | 1 year ago | 2 months ago |
|
|
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
Nautobot may allows uploaded media files to be accessible without authentication | Unknown | 2 months ago | 2 months ago |
|
|
nautobot has reflected Cross-site Scripting potential in all object list views | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
Unauthenticated views may expose information to anonymous users | Low Risk 3.7 | 2 months ago | 2 months ago |
|
|
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
No summary available | Unknown | 2 years ago | 3 months ago |
|
|
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects | Medium Risk 6.3 | 2 years ago | 3 months ago |
|
|
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating | Medium Risk 6.0 | 1 year ago | 3 months ago |
|
|
No summary available | High Risk 7.1 | 1 year ago | 3 months ago |
|
|
Nautobot missing object-level permissions enforcement when running Job Buttons | Low Risk 3.5 | 2 years ago | 3 months ago |
|
|
No summary available | Medium Risk 5.3 | 2 years ago | 3 months ago |
|
|
No summary available | Medium Risk 4.3 | 2 years ago | 3 months ago |
|
|
Cross-site Scripting potential in custom links, job buttons, and computed fields | High Risk 7.1 | 2 years ago | 1 year ago |
|
|
No summary available | Medium Risk 5.4 | 2 years ago | 1 year ago |
|
|
No summary available | Medium Risk 6.5 | 2 years ago | 1 year ago |
|
|
Nautobot vulnerable to remote code execution via Jinja2 template rendering | High Risk 7.5 | 3 years ago | 2 years ago |
|
|
No summary available | Medium Risk 5.4 | 2 years ago | 2 years ago |
|
|
No summary available | Medium Risk 6.5 | 2 years ago | 2 years ago |
|
|
No summary available | Unknown | 3 years ago | 2 years ago |
Page 1