Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-10-24T14:17:52.830Z

Updated: 2024-09-11T17:02:05.910Z

Reserved: 2023-10-16T17:51:35.572Z

Link: CVE-2023-46128

cve-icon Vulnrichment

Updated: 2024-08-02T20:37:39.490Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-25T18:17:36.607

Modified: 2023-11-01T16:25:12.523

Link: CVE-2023-46128

cve-icon Redhat

No data.