Cross-site scripting in Nautobot - CVE-2024-23345
Published: January 26, 2024
Nautobot
Nautobot
Description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the rendered Markdown fields. A remote user can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- https://github.com/nautobot/nautobot/security/advisories/GHSA-v4xv-795h-rv4h
- https://github.com/nautobot/nautobot/pull/5133
- https://github.com/nautobot/nautobot/pull/5134
- https://github.com/nautobot/nautobot/commit/17effcbe84a72150c82b138565c311bbee357e80
- https://github.com/nautobot/nautobot/commit/64312a4297b5ca49b6cdedf477e41e8e4fd61cce