CVE-2025-62607

MEDIUM

nautobot-ssot < 3.10.0 - Unauthenticated Information Disclosure via Configuration Page

Title source: llm
STIX 2.1

Description

Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view the Service Now public instance name e.g. companyname.service-now.com. This is considered low-value information. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page. This issue has been patched in version 3.10.0.

Scores

CVSS v3 5.3
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (2)
nautobot/nautobot-app-ssot < 3.10.0
pypi/nautobot-ssot 0 - 3.10.0PyPI
Published Oct 22, 2025
Tracked Since Feb 18, 2026