CVE-2023-51649
Description
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level extras.run_job permission is checked (i.e., does the user have permission to run Jobs in general). Object-level permissions (i.e., does the user have permission to run this specific Job?) are not enforced by the URL/view used in this case. A user with permissions to run even a single Job can actually run all configured JobButton Jobs. Fix will be available in Nautobot 1.6.8 and 2.1.0
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nautobotPyPI | >= 1.5.14, < 1.6.8 | 1.6.8 |
nautobotPyPI | >= 2.0.0, < 2.1.0 | 2.1.0 |
Affected products
3Patches
Vulnerability mechanics
References
9- github.com/nautobot/nautobot/pull/4993nvdIssue TrackingPatchWEB
- github.com/nautobot/nautobot/pull/4995nvdIssue TrackingPatchWEB
- github.com/nautobot/nautobot/security/advisories/GHSA-vf5m-xrhm-v999nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-vf5m-xrhm-v999ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-51649ghsaADVISORY
- github.com/nautobot/nautobot/commit/3d964f996f4926126c1d7853ca87b2ff475997a2ghsaWEB
- github.com/nautobot/nautobot/commit/d33d0c15a36948c45244e5b5e10bc79b8e62de7fghsaWEB
- github.com/nautobot/nautobot/issues/4988nvdIssue TrackingWEB
- github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2023-287.yamlghsaWEB
News mentions
0No linked articles in our index yet.