Skip to content
Threat Feed
medium advisory

Information Disclosure Vulnerability in NetBox

An authenticated remote attacker can exploit a vulnerability in NetBox to perform information disclosure through improper request handling.

CVE search metadata

CVE search record: CVE-2024-43403. Severity: high. CVSS: 8.8. EPSS: 0.52%. KEV: no. Product: NetBox. Brief: Information Disclosure Vulnerability in NetBox. Brief link: https://feed.craftedsignal.io/briefs/2026-10-netbox-info-disclosure/

NetBox Labs has identified a security vulnerability in NetBox that allows for unauthorized information disclosure. A remote, authenticated attacker can leverage this flaw by sending specifically crafted requests to the application. The vulnerability stems from improper handling of certain data requests, which results in the exposure of sensitive information that should otherwise be restricted. This issue impacts the confidentiality of the environment metadata and configuration data stored within the platform. Defenders should prioritize auditing internal access to the NetBox application and reviewing server logs for anomalous patterns during authenticated sessions to identify potential attempts to exploit this information disclosure vulnerability.

Impact

Successful exploitation of this vulnerability allows an authenticated attacker to gain unauthorized access to sensitive information stored within the NetBox instance, such as network topology, infrastructure configuration, and device details. This exposure can provide an attacker with reconnaissance data necessary to facilitate further lateral movement or targeted attacks within the organization's network environment.

Recommendation

Prioritize the identification of all internal NetBox instances and review current authentication and authorization logs. Ensure the application is patched to the latest version provided by NetBox Labs to mitigate the information disclosure flaw. Monitor web access logs for unusual patterns of GET requests to metadata-sensitive endpoints by existing user accounts that deviate from established administrative or service account behavior.


Immediate actions

Patch NetBox to the latest version.

IT Operations 72h

Threat Hunt

Anomalous GET requests to API endpoints from authenticated users

T1592 medium medium confidence defer

Data: Web server access logs

Mitigations

Review access logs for authenticated users requesting unusual data paths.

immediate SOC

CVE-2024-43403