VYPR
High severity7.5NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026

CVE-2024-34707

CVE-2024-34707

Description

Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the BANNER_TOP, BANNER_BOTTOM, and BANNER_LOGIN configuration settings via the /admin/constance/config/ endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of BANNER_LOGIN) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nautobotPyPI
< 1.6.221.6.22
nautobotPyPI
>= 2.0.0, < 2.2.42.2.4

Affected products

3
  • Nautobot/Nautobot2 versions
    cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*range: <1.6.22
    • (no CPE)range: < 1.6.22
  • ghsa-coords
    Range: < 1.6.22

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.