Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GraphQL queries are not properly checked for authorisation #377

Closed
peteeckel opened this issue Aug 29, 2024 · 0 comments · Fixed by #378
Closed

GraphQL queries are not properly checked for authorisation #377

peteeckel opened this issue Aug 29, 2024 · 0 comments · Fixed by #378
Assignees
Labels
bug Something isn't working

Comments

@peteeckel
Copy link
Owner

Versions
NetBox Version: 4.0.10
NetBox DNS Version: 1.0.6
Python Version: 3.11.5

Describe the bug
It is possible to retrieve data from all plugin models via GraphQL without proper authentication. This has been detected in NetBox netbox-community/netbox#16292 and fixed in NetBox 4.0.10.

To Reproduce
See the referenced NetBox bug. This also works with plugin models.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant