netbox-proxbox icon indicating copy to clipboard operation
netbox-proxbox copied to clipboard

dont show token value on proxbox plugin page

Open ITJamie opened this issue 2 years ago • 1 comments

when visiting the proxbox plugin page: eg demo.netbox.dev/plugins/proxbox/ the user token is displayed in full. this should be considered a secret and not shown in the gui

ITJamie avatar Dec 11 '23 21:12 ITJamie

This was caught during an infrastructure audit at an organization I'm active at, and would have allowed root access to all VMs (via the VM.Monitor permission).

Even worse, default NetBox installations seem to show the plugins page / details even to logged out users...

q3k avatar Apr 11 '24 18:04 q3k