CVE-2024-36112 is a medium-severity vulnerability affecting Nautobot versions 1.3.0-1.6.22 and 2.0.0-2.2.4, where users with 'extras.view_dynamicgroup' permission can view all members of a Dynamic Group, bypassing individual object permissions. This allows unauthorized disclosure of sensitive information, such as device details, without requiring complex attack methods. While there is no evidence of active exploitation or public exploit code, and minimal community discussion, users are strongly advised to upgrade to Nautobot 1.6.23 or 2.2.5 to mitigate this information disclosure risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.0, < 1.6.23CPE matchmatch criteria | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.2.5CPE matchmatch criteria | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.