CVE-2024-29199
Last modified
CVE-2024-29199 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthenticated user unless the Nautobot configuration variable EXEMPT_VIEW_PERMISSIONS is changed from its default value (an empty list) to permit access to specific data by unauthenticated users. This vulnerability is fixed in 1.6.16 and 2.1.9.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Networktocode | Nautobot | < 1.6.16 |
| Networktocode | Nautobot | >= 2.0.0, < 2.1.9 |
References
- https://github.com/nautobot/nautobot/security/advisories/GHSA-m732-wvh2-7cq4Third Party Advisory
- https://github.com/nautobot/nautobot/security/advisories/GHSA-m732-wvh2-7cq4Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-29199?
How severe is CVE-2024-29199?
How do I fix CVE-2024-29199?
Are you affected by CVE-2024-29199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
