Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-51649

Опубликовано: 22 дек. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 4.3
EPSS Низкий

Описание

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level extras.run_job permission is checked (i.e., does the user have permission to run Jobs in general). Object-level permissions (i.e., does the user have permission to run this specific Job?) are not enforced by the URL/view used in this case. A user with permissions to run even a single Job can actually run all configured JobButton Jobs. Fix will be available in Nautobot 1.6.8 and 2.1.0

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
Версия от 1.5.14 (включая) до 1.6.8 (исключая)
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.1.0 (исключая)

EPSS

Процентиль: 29%
0.00103
Низкий

3.5 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 3.5
github
около 2 лет назад

Nautobot missing object-level permissions enforcement when running Job Buttons

EPSS

Процентиль: 29%
0.00103
Низкий

3.5 Low

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-863