nautobot is vulnerable to Information Disclosure
65
Medium Risk
Nautobot's REST API supports traversing from a requested object to its related objects using the ?depth query parameter. Object-level view permissions are enforced for the root object but not for related objects reached through traversal, so a user with limited permissions can read the full detail of related objects outside their granted scope. This results in disclosure of information the user is not authorized to see. The fix restricts related objects the user cannot view to a brief representation exposing only id, object_type, url, and display.
You are affected if you are using a version that falls within the vulnerable range and you have REST API users with limited object-level permissions who traverse to related objects using the ?depth query parameter.
nautobot is vulnerable to Information Disclosure in versions 0.0.1 - 2.4.37 and 3.0.0 - 3.1.8.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant