cve/2023/CVE-2023-33796.md
2024-06-18 02:51:15 +02:00

831 B

CVE-2023-33796

Description

** DISPUTED ** A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.

POC

Reference

Github