VYPR
Low severity3.5NVD Advisory· Published Dec 22, 2023· Updated Jun 17, 2026

CVE-2023-51649

CVE-2023-51649

Description

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level extras.run_job permission is checked (i.e., does the user have permission to run Jobs in general). Object-level permissions (i.e., does the user have permission to run this specific Job?) are not enforced by the URL/view used in this case. A user with permissions to run even a single Job can actually run all configured JobButton Jobs. Fix will be available in Nautobot 1.6.8 and 2.1.0

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nautobotPyPI
>= 1.5.14, < 1.6.81.6.8
nautobotPyPI
>= 2.0.0, < 2.1.02.1.0

Affected products

3
  • Nautobot/Nautobot2 versions
    cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*range: >=1.5.14,<1.6.8
    • (no CPE)range: >= 1.5.14, < 1.6.8
  • ghsa-coords
    Range: >= 1.5.14, < 1.6.8

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.