CVE-2025-62607

Nautobot Single Source of Truth (SSoT) is an app for Nautobot. Prior to version 3.10.0, an unauthenticated attacker could access this page to view the Service Now public instance name e.g. companyname.service-now.com. This is considered low-value information. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page. This issue has been patched in version 3.10.0.
Configurations

No configuration.

History

22 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-22 16:15

Updated : 2025-10-22 21:12


NVD link : CVE-2025-62607

Mitre link : CVE-2025-62607

CVE.ORG link : CVE-2025-62607


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function