VDB
Sign up
MEDIUM5.3

PYSEC-2026-1690

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Quick fix

PYSEC-2026-1690 — nautobot-ssot: upgrade to the fixed version with the command below.

pip install --upgrade 'nautobot-ssot>=3.10.0'

Details

The servicenow config URL is using a generic django View with no authentication.

URL: `/plugins/ssot/servicenow/config/`

### Impact _What kind of vulnerability is it? Who is impacted?_ An Unauthenticated attacker could access this page to view the Service Now public instance name e.g. `companyname.service-now.com`. This is considered **low-value information**. This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page.

### Patches _Has the problem been patched? What versions should users upgrade to?_ We highly recommend upgrading to SSoT v3.10.0 which includes this patch.

### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ Disable the servicenow SSoT integration

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nautobot-ssot
Introduced in: 0Fixed in: 3.10.0
Fixpip install --upgrade 'nautobot-ssot>=3.10.0'

References