NetBox 版本至 4.7.0 存在一个漏洞:在 REST 和 GraphQL API 的响应中,未能对数据源后端(如 Git 和 Amazon S3)的敏感凭据进行屏蔽。仅具有查看权限的认证用户可通过 API 端点获取明文密码和密钥,从而获得对外部代码仓库和存储桶的未授权访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| netbox-community | netbox | ≤ 4.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netbox-community | netbox | 0 ~ 4.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet