Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4xv-795h-rv4h

Опубликовано: 23 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

Impact

All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted.

Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including:

  • Circuit.comments
  • Cluster.comments
  • CustomField.description
  • Device.comments
  • DeviceRedundancyGroup.comments
  • DeviceType.comments
  • Job.description
  • JobLogEntry.message
  • Location.comments
  • Note.note
  • PowerFeed.comments
  • Provider.noc_contact
  • Provider.admin_contact
  • Provider.comments
  • ProviderNetwork.comments
  • Rack.comments
  • Tenant.comments
  • VirtualMachine.comments
  • Contents of any custom fields of type markdown
  • Job class description attributes
  • The SUPPORT_MESSAGE system configuration setting

are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data.

Patches

Fixed in Nautobot versions 1.6.10 and 2.1.2.

References

https://github.com/nautobot/nautobot/pull/5133 https://github.com/nautobot/nautobot/pull/5134

Пакеты

Наименование

nautobot

pip
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.2

2.1.2

Наименование

nautobot

pip
Затронутые версииВерсия исправления

< 1.6.10

1.6.10

EPSS

Процентиль: 61%
0.00412
Низкий

7.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
nvd
около 2 лет назад

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.

EPSS

Процентиль: 61%
0.00412
Низкий

7.1 High

CVSS3

Дефекты

CWE-79