{"id":"CVE-2025-62607","aliases":["GHSA-535g-62r7-cx6v","PYSEC-2026-1690"],"title":"Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL","summary":"Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","vendor":"nautobot-ssot","product":"nautobot-ssot","ecosystem":"pip","affected":["nautobot-ssot < 3.10.0"],"patched":["nautobot-ssot 3.10.0"],"published":"2025-10-21","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-535g-62r7-cx6v","references":[{"url":"https://github.com/nautobot/nautobot-app-ssot/security/advisories/GHSA-535g-62r7-cx6v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-62607"},{"url":"https://github.com/nautobot/nautobot-app-ssot/commit/1530d25cdeb929641ec47644f9a0a1d9d41e1cb8"},{"url":"https://github.com/nautobot/nautobot-app-ssot"},{"url":"https://github.com/nautobot/nautobot-app-ssot/releases/tag/v3.10.0"}],"tags":["osv","pip"],"epss":0.00294,"epssPercentile":0.22305,"ingestedAt":"2026-07-08T18:25:45.745Z","slug":"CVE-2025-62607","body":"## Overview\n\nThe servicenow config URL is using a generic django View with no authentication.\n\nURL: `/plugins/ssot/servicenow/config/`\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\nAn Unauthenticated attacker could access this page to view the Service Now public instance name e.g. `companyname.service-now.com`. This is considered **low-value information**.  This does not expose the Secret, the Secret Name, or the Secret Value for the Username/Password for Service-Now.com. An unauthenticated member would not be able to change the instance name, nor set a Secret. There is not a way to gain access to other pages Nautobot through the unauthenticated Configuration page.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\nWe highly recommend upgrading to SSoT v3.10.0 which includes this patch.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nDisable the servicenow SSoT integration\n\n## Affected packages\n\n- `nautobot-ssot < 3.10.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nautobot-ssot 3.10.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}