216.73.216.197

CVE-2025-49143

· Published 10/06/2025 16:15 · Modified 10/06/2025 16:15

Labels: CVE-2025-49143 2025-06-10CVE-2025-49143CWE-200[email protected]

Essential information

Published
10/06/2025 16:15
Modified
10/06/2025 16:15
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device, or Rack, are served to users via a URL endpoint that was not enforcing user authentication. As a consequence, such files can be retrieved by anonymous users who know or can guess the correct URL for a given file. Nautobot v2.4.10 and v1.6.32 address this issue by adding enforcement of Nautobot user authentication to this endpoint.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
nautobot / nautobot cpe:2.3:a:nautobot:nautobot:<2.4.10:*:*:*:*:*:*:*
nautobot / nautobot cpe:2.3:a:nautobot:nautobot:<1.6.32:*:*:*:*:*:*:*

References