目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

nautobot 厂商漏洞列表 / CVE 中文分析 15

nautobot 厂商相关 15 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Nautobot 是网络基础设施自动化平台,用于网络设备配置、监控和文档管理。历史上常见漏洞包括远程代码执行、跨站脚本请求伪造和权限绕过,主要源于身份验证机制和API接口缺陷。截至最新统计,该项目已记录15条CVE,多数涉及未授权访问和输入验证问题。安全团队建议及时更新版本并实施严格的访问控制,以缓解潜在风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-34203 Nautobot: Management of users via REST API does not apply configured password validators — nautobotCWE-521 2.7 Low2026-03-31
CVE-2025-62607 Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL — nautobot-app-ssotCWE-306 5.3 Medium2025-10-22
CVE-2025-49143 Nautobot may allows uploaded media files to be accessible without authentication — nautobotCWE-200 7.5AIHighAI2025-06-10
CVE-2025-49142 Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating — nautobotCWE-1336 8.1AIHighAI2025-06-10
CVE-2024-36112 Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects — nautobotCWE-280 6.3 Medium2024-05-28
CVE-2024-34707 Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages — nautobotCWE-79 7.5 High2024-05-13
CVE-2024-32979 Reflected Cross-site Scripting potential in all object list views in Nautobot — nautobotCWE-79 7.5 High2024-05-01
CVE-2024-29199 Unauthenticated views may expose information to anonymous users — nautobotCWE-200 3.7 Low2024-03-26
CVE-2024-23345 Nautobot has XSS potential in rendered Markdown fields — nautobotCWE-79 7.1 High2024-01-22
CVE-2023-51649 Nautobot missing object-level permissions enforcement when running Job Buttons — nautobotCWE-863 3.5 Low2023-12-22
CVE-2023-50263 Nautobot allows unauthenticated db-file-storage views — nautobotCWE-200 3.7 Low2023-12-12
CVE-2023-48705 nautobot has XSS potential in custom links, job buttons, and computed fields — nautobotCWE-79 7.1 High2023-11-22
CVE-2023-48700 Clear Text Credentials Exposed via Onboarding Task — nautobot-plugin-device-onboardingCWE-256 5.7 Medium2023-11-21
CVE-2023-46128 Exposure of hashed user passwords via REST API in Nautobot — nautobotCWE-200 6.5 Medium2023-10-24
CVE-2023-25657 Remote code execution in Jinja2 template rendering in Nautobot — nautobotCWE-94 7.5 High2023-02-21

本页汇总了 nautobot 厂商截至目前公开的全部 15 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。