nautobot is vulnerable to Information Disclosure
85
High Risk
Nautobot injects the entire Django settings object into template contexts and the settings_or_config filter resolves any requested name directly against Django settings. Any authenticated user who can render a Jinja2 template can read sensitive configuration values such as SECRET_KEY, database credentials, and integration secrets. No elevated permissions are required to reach the disclosure through template rendering. The fix restricts the filter and the template settings context to a non-sensitive allowlist of settings and configuration values.
You are affected if you are using a version that falls within the vulnerable range and you allow authenticated users to render Jinja2 templates.
nautobot is vulnerable to Information Disclosure in versions 0.0.1 - 2.4.37 and 3.0.0 - 3.1.8.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant