Description
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-object references via GenericForeignKey (a pattern allowing an object to reference another object that may belong to one of several different -content types- or database tables), when creating or updating an object containing a GenericForeignKey, Nautobot-s REST API failed to enforce user -view- permissions when determining whether a given reference to another object would be valid. This vulnerability is fixed in 2.4.33 and 3.1.2.
CVSS 5.4EPSS 0.17700000000000002%Risque 0.55
Voir la source- Publication
- 2026-05-28 18:16:33
- Versions concernées
- <2.4.33,<3.1.2
- Type
- Core software
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N