Skip to content

Clear Text Credentials Exposed via Onboarding Task

Moderate severity GitHub Reviewed Published Nov 21, 2023 in nautobot/nautobot-app-device-onboarding • Updated Nov 30, 2023

Package

pip nautobot-device-onboarding (pip)

Affected versions

>= 2.0.0, < 3.0.0

Patched versions

3.0.0

Description

Impact

When credentials are provided while creating an OnboardingTask they may be visible via the Job Results view under the Additional Data tab as args for the Celery Task execution. This only applies to OnboardingTasks that are created with credentials specified while on v2.0.0-2.0.2 of Nautobot Device Onboarding. This advisory does not apply earlier version or when using NAPALM_USERNAME & NAPALM_PASSWORD from nautobot_config.py

Patches

v3.0.0

Workarounds

None

Recommendations

  • Delete all Job Results for any onboarding task to remove clear text credentials from database entries that were run while on v2.0.X
  • Upgrade to v3.0.0
  • Rotate any exposed credential

References

Published by the National Vulnerability Database Nov 21, 2023
Published to the GitHub Advisory Database Nov 21, 2023
Reviewed Nov 21, 2023
Last updated Nov 30, 2023

Severity

Moderate
5.7
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CVE ID

CVE-2023-48700

GHSA ID

GHSA-qf3c-rw9f-jh7v

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.