Glenn Matthews
24 exploits
Active since Oct 2023
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVSS 5.4
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVSS 6.5
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVSS 8.5
Nautobot: GitRepository.current_head field should not be writable through REST API
CVSS 7.1
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVSS 5.4
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVSS 6.5
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVSS 8.5
Nautobot: GitRepository.current_head field should not be writable through REST API
CVSS 7.1
Nautobot < 1.6.6 and 2.0.0-2.0.4 - Stored Cross-Site Scripting via Custom Links and Job Buttons
CVSS 7.1
Nautobot 1.x-2.0.x < 1.6.7/2.0.6 - Unauthenticated Arbitrary File Download via FileProxy Endpoints
CVSS 3.7
Nautobot < 1.6.10 and 2.0.0-2.1.2 - Stored Cross-Site Scripting via Markdown Rendering
CVSS 7.1
Nautobot < 1.6.16 - Unauthenticated Exposure of Sensitive Information via URL Endpoints
CVSS 3.7
Nautobot < 1.6.22 - Authenticated Stored Cross-Site Scripting via Banner Configuration
CVSS 7.5
Nautobot < 1.6.32 - Unauthenticated Exposure of Sensitive Information via MEDIA_ROOT URL Endpoint
CVSS 5.9
Nautobot: Management of users via REST API does not apply configured password validators
CVSS 2.7
Nautobot: Management of users via REST API does not apply configured password validators
CVSS 2.7
Nautobot 2.0.0-2.0.2 - Authenticated Exposure of Hashed User Passwords via REST API Depth Parameter
CVSS 6.5
Nautobot < 1.6.6 and 2.0.0-2.0.4 - Stored Cross-Site Scripting via Custom Links and Job Buttons
CVSS 7.1
Nautobot 1.x-2.0.x < 1.6.7/2.0.6 - Unauthenticated Arbitrary File Download via FileProxy Endpoints
CVSS 3.7
Nautobot < 1.6.10 and 2.0.0-2.1.2 - Stored Cross-Site Scripting via Markdown Rendering
CVSS 7.1
Nautobot < 1.6.16 - Unauthenticated Exposure of Sensitive Information via URL Endpoints
CVSS 3.7
Nautobot 1.5.0-1.6.19 - Reflected Cross-Site Scripting via Filterable Object-List Views
CVSS 7.5
Nautobot < 1.6.22 - Authenticated Stored Cross-Site Scripting via Banner Configuration
CVSS 7.5
Nautobot < 1.6.32 - Unauthenticated Exposure of Sensitive Information via MEDIA_ROOT URL Endpoint
CVSS 5.9