NetBox是NetBox社区开源的一款网络基础设施管理平台。 NetBox 4.5.8及之前版本存在授权问题漏洞,该漏洞源于ORM注入,经过身份验证的攻击者通过向REST API端点提交特制JSON字典键,可将任意Django ORM查找表达式注入嵌套对象引用,导致敏感字段值泄露和绕过对象级权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NetBox Labs | NetBox | ≤ 4.5.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NetBox Labs | NetBox | 0 ~ 4.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet