NetBox是NetBox社区的一款基于Django、PostgreSql 用于IP地址管理(IPAM)和数据中心基础结构管理(DCIM)的工具。 NetBox 4.3.5版本至4.5.4版本存在安全漏洞,该漏洞源于RenderTemplateMixin.get_environment_params()方法中存在远程代码执行,允许具有exporttemplate或configtemplate权限的认证用户通过在environment_params字段中指定恶意Python可调用对象执行任意代码,攻击者可以
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| netbox-community | netbox | 4.3.5≤ 4.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netbox-community | netbox | 4.3.5 ~ 4.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet