All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted.
Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including:
Circuit.comments
Cluster.comments
CustomField.description
Device.comments
DeviceRedundancyGroup.comments
DeviceType.comments
Job.description
JobLogEntry.message
Location.comments
Note.note
PowerFeed.comments
Provider.noc_contact
Provider.admin_contact
Provider.comments
ProviderNetwork.comments
Rack.comments
Tenant.comments
VirtualMachine.comments
markdown
description
attributesSUPPORT_MESSAGE
system configuration settingare potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data.
Fixed in Nautobot versions 1.6.10 and 2.1.2.
https://github.com/nautobot/nautobot/pull/5133 https://github.com/nautobot/nautobot/pull/5134
{ "nvd_published_at": "2024-01-23T00:15:26Z", "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-23T14:44:22Z" }