Description
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0116 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2. |
Github GHSA |
GHSA-v4xv-795h-rv4h | XSS potential in rendered Markdown fields (comments, description, notes, etc.) |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T14:21:39.846Z
Reserved: 2024-01-15T15:19:19.445Z
Link: CVE-2024-23345
No data.
Status : Modified
Published: 2024-01-23T00:15:26.690
Modified: 2024-11-21T08:57:33.283
Link: CVE-2024-23345
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA