NetBox through 4.7.0 Information Disclosure via REST and GraphQL APIs
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 75% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
netbox-community · netbox⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/geo-chen/oss/blob/main/netbox.md#finding-1-cross-user-disclosure-of-private-notifications-subscriptions-and-bookmarks-via-rest-api-and-graphql-missing-per-user-scopinghttps://github.com/netbox-community/netboxhttps://github.com/netbox-community/netbox/blob/v4.7.0/netbox/extras/api/views.py#L153-L178https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/netbox/settings.py#L667-L673https://www.vulncheck.com/advisories/netbox-through-4.7.0-information-disclosure-via-rest-and-graphql-apis