nautobot is vulnerable to Improper Authorization
43
Medium Risk
The legacy /api/dcim/console-connections/, /api/dcim/power-connections/, and /api/dcim/interface-connections/ REST API endpoints build their querysets without applying object-level permission constraints. A low-privileged authenticated user can enumerate connections and read descriptions, types, tags, and custom field values they should not access. The fix restricts these querysets to the requesting user's permitted objects and stops serializing details of a peer the requester cannot view.
You are affected if you are using a version that falls within the vulnerable range and you rely on ObjectPermission constraints to scope which console, power, or interface connections users may view through the legacy DCIM connections REST API endpoints.
nautobot is vulnerable to Improper Authorization in versions 0.0.1 - 2.4.39 and 3.0.0 - 3.2.2.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant