nautobot@2.4.28

Source of truth and network automation platform.

  • latest version

    3.2.2

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    9 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the nautobot package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Missing Authorization

    nautobot is a Source of truth and network automation platform.

    Affected versions of this package are vulnerable to Missing Authorization in the GenericForeignKey process. An attacker can associate objects with unauthorized resources by supplying the UUIDs of objects they do not have permission to view when creating or updating records via the REST API.

    How to fix Missing Authorization?

    Upgrade nautobot to version 2.4.33, 3.1.2 or higher.

    [,2.4.33)[3.0.0a2,3.1.2)
    • H
    Regular Expression Denial of Service (ReDoS)

    nautobot is a Source of truth and network automation platform.

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the find field in combination with the use_regex flag in the object bulk rename process. An attacker can cause the application to become unresponsive by submitting a maliciously crafted regular expression that leads to excessive resource consumption during evaluation.

    How to fix Regular Expression Denial of Service (ReDoS)?

    Upgrade nautobot to version 2.4.33, 3.1.2 or higher.

    [,2.4.33)[3.0.0a2,3.1.2)
    • H
    Server-side Request Forgery (SSRF)

    nautobot is a Source of truth and network automation platform.

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the Webhook process. An attacker can access internal or restricted network resources by configuring webhooks to send requests to unauthorized hosts or IP addresses.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade nautobot to version 2.4.33, 3.1.2 or higher.

    [,2.4.33)[3.0.0a2,3.1.2)
    • H
    Exposed Dangerous Method or Function

    nautobot is a Source of truth and network automation platform.

    Affected versions of this package are vulnerable to Exposed Dangerous Method or Function via the current_head field in the REST API. An attacker can manipulate the state of local repository clones or render them unusable by setting this field to an arbitrary or malformed value.

    How to fix Exposed Dangerous Method or Function?

    Upgrade nautobot to version 2.4.33, 3.1.2 or higher.

    [,2.4.33)[3.0.0a2,3.1.2)
    • M
    Weak Password Requirements

    nautobot is a Source of truth and network automation platform.

    Affected versions of this package are vulnerable to Weak Password Requirements in the REST API for user management. An attacker can set weak or non-compliant passwords for user accounts by bypassing configured password validation rules.

    How to fix Weak Password Requirements?

    Upgrade nautobot to version 2.4.30, 3.0.10 or higher.

    [,2.4.30)[3.0.0a2,3.0.10)