You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
when visiting the proxbox plugin page: eg demo.netbox.dev/plugins/proxbox/ the user token is displayed in full. this should be considered a secret and not shown in the gui
The text was updated successfully, but these errors were encountered:
This was caught during an infrastructure audit at an organization I'm active at, and would have allowed root access to all VMs (via the VM.Monitor permission).
Even worse, default NetBox installations seem to show the plugins page / details even to logged out users...
q3k
added a commit
to q3k/netbox-proxbox
that referenced
this issue
Apr 11, 2024
when visiting the proxbox plugin page: eg demo.netbox.dev/plugins/proxbox/ the user token is displayed in full. this should be considered a secret and not shown in the gui
The text was updated successfully, but these errors were encountered: