Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nautobot: GitRepository.current_head field should not be writable through REST API
Vulnerability Description
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to add/change a GitRepository record could use the REST API to directly set the current_head field on the record, which was not intended to be user-editable. Doing so could cause Nautobot's local clone(s) of the relevant repository to checkout a commit other than the latest commit on the specified branch (resulting in misleading state), or potentially to be unable to make use of the repository at all (until manually remediated) due to the current_head pointing to a nonexistent commit hash or malformed value. This vulnerability is fixed in 2.4.33 and 3.1.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
对假设不可变数据的修改(MAID)
Vulnerability Title
Nautobot 安全漏洞
Vulnerability Description
Nautobot是Nautobot个人开发者的一个网络自动化平台。 Nautobot 2.4.33之前版本和3.1.2之前版本存在安全漏洞,该漏洞源于具有添加/更改GitRepository记录权限的用户可通过REST API直接设置current_head字段,导致本地克隆检出非最新提交或指向不存在的提交哈希,造成误导性状态或无法使用仓库。
CVSS Information
N/A
Vulnerability Type
N/A