漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Vulnerability Description
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook data model and associated feature set could be configured by users with sufficient access to perform requests to various hosts and IP addresses that should not be permitted, allowing for various behaviors similar to server-side request forgery (SSRF). This vulnerability is fixed in 2.4.33 and 3.1.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Nautobot 代码问题漏洞
Vulnerability Description
Nautobot是Nautobot个人开发者的一个网络自动化平台。 Nautobot 2.4.33之前版本和3.1.2之前版本存在代码问题漏洞,该漏洞源于Webhook数据模型和相关功能集可被具有足够权限的用户配置为向不应允许的主机和IP地址发送请求,导致类似服务端请求伪造的行为。
CVSS Information
N/A
Vulnerability Type
N/A