Replies: 3 comments 4 replies
-
Am I reading it right that the vulnerability requires the credentials or otherwise access to the system and the ability to add custom scripts? If that's the case, that would be yet another case of a cve mill. |
Beta Was this translation helpful? Give feedback.
-
So, a user with permissions to add scripts is able to add scripts, is that it? Sounds clickbait to me, the blog does not work and the images in linkedin were very unspecific about the actual problems. But someone else feel free to comment. |
Beta Was this translation helpful? Give feedback.
-
Nuisance CVE reports are becoming a more and more frequent problem in open source, unfortunately. People intent on farming reports (for clout, presumably) submit issues without any consideration for whether the behavior imposes an actual vulnerability. I highly recommend this article on the topic, which few people interested in addressing. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
CVE-2024-23780 has been announced (see https://hazardlab.io/netbox-cve-2024-23780-writeup).
I did not find an issue open and am new to NetBox so I held off on opening the issue. Our use of NetBox
is behind a reverse proxy that requires authentication even to access NetBox so the issue is not one
that impacts us but it does not appear Hazardlab reported this issue to NetBox so I report it here.
Beta Was this translation helpful? Give feedback.
All reactions