Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=<N>` query parameter, can expose hashed user passwords as stored in the database to any authenticated user with access to these endpoints. The passwords are not exposed in plaintext. This vulnerability has been patched in version 2.0.3.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-24T14:17:52.830Z
Updated: 2024-09-11T17:02:05.910Z
Reserved: 2023-10-16T17:51:35.572Z
Link: CVE-2023-46128
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T20:37:39.490Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-10-25T18:17:36.607
Modified: 2024-11-21T08:27:56.323
Link: CVE-2023-46128
 Redhat
                        Redhat
                    No data.