VYPR
High severity7.1NVD Advisory· Published Jan 23, 2024· Updated Jun 17, 2026

CVE-2024-23345

CVE-2024-23345

Description

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nautobotPyPI
>= 2.0.0, < 2.1.22.1.2
nautobotPyPI
< 1.6.101.6.10

Affected products

3
  • Nautobot/Nautobot2 versions
    cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*range: <1.6.10
    • (no CPE)range: >= 2.0.0, < 2.1.2
  • ghsa-coords
    Range: >= 2.0.0, < 2.1.2

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.