nautobot is vulnerable to Information Disclosure
65
Medium Risk
Nautobot's GraphQL implementation enforces object-level permissions only at the root of a query and not when traversing the object graph into related models. A user with access to some models but not others can craft a GraphQL query that retrieves fields from related objects they are not authorized to view. This exposes data across foreign-key, reverse-relation, relationship, and property-backed accessors. The fix enforces object-level view permissions during traversal, returning null or filtered lists for objects the user cannot view.
You are affected if you are using a version that falls within the vulnerable range and you have users with limited object-level permissions who can run GraphQL queries.
nautobot is vulnerable to Information Disclosure in versions 0.0.1 - 2.4.37 and 3.0.0 - 3.1.8.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant