{"id":"CVE-2025-62607","aliases":["GHSA-535g-62r7-cx6v","PYSEC-2026-1690"],"url":"https://o3.security/vulnerability/CVE-2025-62607","summary":"Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL","details":"The servicenow config URL is using a generic django View with no authentication.\n\nURL: `/plugins/ssot/servicenow/config/`\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\nAn Unauthenticated attacker could access this page to view the Service Now public instance name e.g. `companyname.service-now.com`. This is considered **low-value information**.  This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nWe highly recommend upgrading to SSoT v3.10.0 which includes this patch.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nDisable the servicenow SSoT integration","published":"2025-10-22T15:40:46.355Z","modified":"2026-08-12T03:51:37.228075668Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"nautobot-ssot","fixedVersion":"3.10.0"}],"fix":{"url":"https://github.com/nautobot/nautobot-app-ssot/commit/1530d25cdeb929641ec47644f9a0a1d9d41e1cb8","label":"nautobot/nautobot-app-ssot@1530d25"},"references":[{"type":"WEB","url":"https://github.com/nautobot/nautobot-app-ssot/releases/tag/v3.10.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/62xxx/CVE-2025-62607.json"},{"type":"ADVISORY","url":"https://github.com/nautobot/nautobot-app-ssot/security/advisories/GHSA-535g-62r7-cx6v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62607"},{"type":"FIX","url":"https://github.com/nautobot/nautobot-app-ssot/commit/1530d25cdeb929641ec47644f9a0a1d9d41e1cb8"},{"type":"PACKAGE","url":"https://github.com/nautobot/nautobot-app-ssot"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.228075668Z"}}