Impact
NetBox up to and including version 4.7.0 does not redact sensitive credentials for data source backends in its REST and GraphQL API responses. An authenticated user with only view‑level permissions can obtain plaintext passwords and secret keys for Git and Amazon S3 backends via the standard API endpoints, giving the attacker unauthorized access to external code repositories and storage buckets. The weakness is a credential disclosure flaw as defined by CWE-522.
Affected Systems
NetBox software from netbox-community is affected. Any deployment running NetBox 4.7.0 or earlier is vulnerable; versions newer than 4.7.0 are not impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high impact but not critical. Attackers must already have a valid user account with view‑only access, and must query the REST or GraphQL APIs to retrieve the sensitive values. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Given the attack requires user authentication and API access, the exploitability is moderate, but the damage potential from credential leakage is significant.
OpenCVE Enrichment