MEDIUM 5.4
PYSEC-2024-16
Details
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / nautobot
Introduced in:
0 Fixed in: 17effcbe84a72150c82b138565c311bbee357e80 Fix
pip install --upgrade 'nautobot>=17effcbe84a72150c82b138565c311bbee357e80' References
- https://github.com/nautobot/nautobot/security/advisories/GHSA-v4xv-795h-rv4h [ADVISORY]
- https://github.com/nautobot/nautobot/pull/5133 [FIX]
- https://github.com/nautobot/nautobot/pull/5134 [FIX]
- https://github.com/nautobot/nautobot/commit/17effcbe84a72150c82b138565c311bbee357e80 [FIX]
- https://github.com/nautobot/nautobot/commit/64312a4297b5ca49b6cdedf477e41e8e4fd61cce [FIX]