NetBox v3.7.0 vulnerability #15634
Replies: 1 comment
-
FYI I fixed your link. It's CVE farming: People find some way to trigger some low-risk bug or discover some out-of-date dependency and submit a vulnerability report without actually understanding whether the behavior presents real risk. Unfortunately, anyone can file a CVE for anything; the whole process is completely unmoderated and unvalidated AFAICT.
Obviously, an administrator with access to modify the application configuration can enter whatever content they choose, whether via the UI form or by setting it in
That's weird, there's a whole thread in the report spanning January 22-23 where I explain the above to the reporter. This individual has submitted several invalid vulnerability reports. When asked to submit feature requests or bug reports instead, they declined. I suspect this is because such people have zero interest in actually improving open source products in any meaningful way, and are focused instead on how many vulnerabilities they can claim to have found in furtherance of their consulting services or whatever. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi everyone.
Is anyone familiar with this issue?
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0948
I get concerned about it and didn't see any fix on last release.
Beta Was this translation helpful? Give feedback.
All reactions