7.1 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
63 packages
- netbox2netshot
- pkgsRocm.netbox
- pkgsRocm.netbox_4_4
- netboxPlugins.netbox-bgp
- netboxPlugins.netbox-dns
- netboxPlugins.netbox-lists
- python313Packages.pynetbox
- python314Packages.pynetbox
- netboxPlugins.netbox-qrcode
- netboxPlugins.netbox-routing
- netboxPlugins.netbox-secrets
- python313Packages.netbox-bgp
- python314Packages.netbox-bgp
- python314Packages.netbox-dns
- netboxPlugins.netbox-contract
- netboxPlugins.netbox-security
- netboxPlugins.netbox-documents
- netboxPlugins.netbox-inventory
- netboxPlugins.netbox-lifecycle
- netboxPlugins.netbox-data-flows
- python314Packages.netbox-qrcode
- netboxPlugins.netbox-attachments
- python313Packages.netbox-routing
- python314Packages.netbox-routing
- netboxPlugins.netbox-contextmenus
- terraform-providers.e-breuninger_netbox
- python313Packages.netbox-dns
- python313Packages.netbox-qrcode
- netboxPlugins.netbox-reorder-rack
- python313Packages.netbox-contract
- netboxPlugins.netbox-config-backup
- netboxPlugins.netbox-napalm-plugin
- python313Packages.netbox-documents
- python314Packages.netbox-documents
- netboxPlugins.netbox-custom-objects
- netboxPlugins.netbox-topology-views
- pkgsRocm.python3Packages.netbox-bgp
- python313Packages.netbox-attachments
- netboxPlugins.netbox-floorplan-plugin
- python313Packages.netbox-contextmenus
- python313Packages.netbox-reorder-rack
- python314Packages.netbox-contextmenus
- python314Packages.netbox-reorder-rack
- pkgsRocm.python3Packages.netbox-qrcode
- python313Packages.netbox-napalm-plugin
- pkgsRocm.python3Packages.netbox-routing
- python313Packages.netbox-topology-views
- pkgsRocm.python3Packages.netbox-contract
- netboxPlugins.netbox-plugin-prometheus-sd
- pkgsRocm.python3Packages.netbox-documents
- python313Packages.netbox-floorplan-plugin
- pkgsRocm.python3Packages.netbox-attachments
- pkgsRocm.python3Packages.netbox-reorder-rack
- pkgsRocm.python3Packages.netbox-napalm-plugin
- python313Packages.netbox-plugin-prometheus-sd
- python314Packages.netbox-plugin-prometheus-sd
- netboxPlugins.netbox-interface-synchronization
- pkgsRocm.python3Packages.netbox-topology-views
- pkgsRocm.python3Packages.netbox-floorplan-plugin
- python313Packages.netbox-interface-synchronization
- python314Packages.netbox-interface-synchronization
- pkgsRocm.python3Packages.netbox-plugin-prometheus-sd
- pkgsRocm.python3Packages.netbox-interface-synchronization
- @LeSuisse restored package pkgsRocm.netbox_4_4
- @LeSuisse accepted
- @LeSuisse published on GitHub
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.
References
-
-
DataSourceSerializer Meta.fields technical-description
-
DataSourceType GraphQL fields technical-description
-
GitBackend sensitive_parameters technical-description
-
GitHub Issue #12625 issue-tracking
Affected products
- =<4.7.0
Matching in nixpkgs
pkgs.netbox
IP address management (IPAM) and data center infrastructure management (DCIM) tool
pkgs.netbox_4_4
None
pkgs.netbox_4_5
None
pkgs.netbox_4_6
IP address management (IPAM) and data center infrastructure management (DCIM) tool
-
nixos-unstable -
- nixos-unstable-small 4.6.8
Ignored packages (62)
pkgs.netbox2netshot
Inventory synchronization tool between Netbox and Netshot
pkgs.pkgsRocm.netbox
None
pkgs.netboxPlugins.netbox-bgp
NetBox plugin for BGP related objects documentation
pkgs.netboxPlugins.netbox-dns
Netbox plugin for managing DNS data
pkgs.netboxPlugins.netbox-lists
NetBox plugin to generate IP and prefix lists. Integrates with Ansible, Terraform, Prometheus, Oxidized and more
pkgs.python313Packages.pynetbox
API client library for Netbox
pkgs.python314Packages.pynetbox
API client library for Netbox
pkgs.netboxPlugins.netbox-qrcode
Netbox plugin for generate QR codes for objects: Rack, Device, Cable
pkgs.netboxPlugins.netbox-routing
NetBox plugin for tracking all kinds of routing information
pkgs.netboxPlugins.netbox-secrets
NetBox plugin to enhance secret management with encrypted storage and flexible, user-friendly features
pkgs.python313Packages.netbox-bgp
None
pkgs.python313Packages.netbox-dns
None
pkgs.python314Packages.netbox-bgp
None
pkgs.python314Packages.netbox-dns
None
pkgs.netboxPlugins.netbox-contract
Contract plugin for netbox
pkgs.netboxPlugins.netbox-security
NetBox plugin covering various security and NAT related models
pkgs.netboxPlugins.netbox-documents
Plugin designed to faciliate the storage of site, circuit, device type and device specific documents within NetBox
pkgs.netboxPlugins.netbox-inventory
NetBox plugin to manage hardware inventory
pkgs.netboxPlugins.netbox-lifecycle
NetBox plugin for managing Hardware EOL/EOS, and Support Contracts
pkgs.netboxPlugins.netbox-data-flows
NetBox plugin to document data flows between systems and applications
pkgs.python313Packages.netbox-qrcode
None
pkgs.python314Packages.netbox-qrcode
None
pkgs.python313Packages.netbox-routing
None
pkgs.python314Packages.netbox-routing
None
pkgs.netboxPlugins.netbox-reorder-rack
NetBox plugin to allow users to reorder devices within a rack using a drag and drop UI
pkgs.python313Packages.netbox-contract
None
pkgs.netboxPlugins.netbox-config-backup
NetBox plugin for configuration backups using napalm
pkgs.netboxPlugins.netbox-napalm-plugin
Netbox plugin for Napalm integration
pkgs.python313Packages.netbox-documents
None
pkgs.python314Packages.netbox-documents
None
pkgs.netboxPlugins.netbox-custom-objects
NetBox plugin to create new object types
pkgs.netboxPlugins.netbox-topology-views
Netbox plugin for generate topology views/maps from your devices
pkgs.pkgsRocm.python3Packages.netbox-bgp
None
pkgs.netboxPlugins.netbox-floorplan-plugin
Netbox plugin providing floorplan mapping capability for locations and sites
pkgs.python313Packages.netbox-reorder-rack
None
pkgs.python314Packages.netbox-reorder-rack
None
pkgs.pkgsRocm.python3Packages.netbox-qrcode
None
pkgs.python313Packages.netbox-napalm-plugin
None
pkgs.pkgsRocm.python3Packages.netbox-routing
None
pkgs.python313Packages.netbox-topology-views
None
pkgs.terraform-providers.e-breuninger_netbox
None
pkgs.pkgsRocm.python3Packages.netbox-contract
None
pkgs.netboxPlugins.netbox-plugin-prometheus-sd
Netbox plugin to provide Netbox entires to Prometheus HTTP service discovery
pkgs.netboxPlugins.netbox-interface-synchronization
Netbox plugin to compare and synchronize interfaces between devices and device types
Package maintainers
-
@minijackson Rémi Nicole <minijackson@riseup.net>
-
@transcaffeine transcaffeine <transcaffeine@finally.coffee>