CVE-2023-50263: Nautobot allows unauthenticated db-file-storage views

Published Dec 12, 2023
·
Updated

Impact

In Nautobot 1.x and 2.0.x, the URLs /files/get/?name=... and /files/download/?name=... are used to provide admin access to files that have been uploaded as part of a run request for a Job that has FileVar inputs. Under normal operation these files are ephemeral and are deleted once the Job in question runs.

It was reported by @kircheneer that in the default implementation used in Nautobot, as provided by django-db-file-storage, these URLs do not by default require any user authentication to access; they should instead be restricted to only users who have permissions to view Nautobot's FileProxy model instances.

Note that no URL mechanism is provided for listing or traversal of the available file name values, so in practice an unauthenticated user would have to guess names to discover arbitrary files for download, but if a user knows the file name/path value, they can access it without authenticating, so we are considering this a vulnerability.

Patches

Fixes will be included in Nautobot 1.6.7 and Nautobot 2.0.6.

Workarounds

No workaround other than applying the patches included in https://github.com/nautobot/nautobot/pull/4959/files (2.0.x) or https://github.com/nautobot/nautobot/pull/4964/files (1.6.x)

References

- https://github.com/victor-o-silva/dbfilestorage/blob/master/dbfilestorage/views.py

Other sources

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs /files/get/?name=... and /files/download/?name=... are used to provide admin access to files that have been uploaded as part of a run request for a Job that has FileVar inputs. Under normal operation these files are ephemeral and are deleted once the Job in question runs.

In the default implementation used in Nautobot, as provided by django-db-file-storage, these URLs do not by default require any user authentication to access; they should instead be restricted to only users who have permissions to view Nautobot's FileProxy model instances.

Note that no URL mechanism is provided for listing or traversal of the available file name values, so in practice an unauthenticated user would have to guess names to discover arbitrary files for download, but if a user knows the file name/path value, they can access it without authenticating, so we are considering this a vulnerability.

Fixes are included in Nautobot 1.6.7 and Nautobot 2.0.6. No known workarounds are available other than applying the patches included in those versions.

Affected Software

4 affected componentsFixes available
pip/nautobot>=2.0.0<2.0.6
2.0.6
pip/nautobot>=1.1.0<1.6.7
1.6.7
Networktocode Nautobot>=1.1.0<1.6.7
Networktocode Nautobot>=2.0.0<2.0.6

Event History

Dec 12, 2023
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverityWeakness
Dec 13, 2023
Advisory Published
01:35 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-50263?

CVE-2023-50263 is classified as a medium severity vulnerability.

2

How do I fix CVE-2023-50263?

To mitigate CVE-2023-50263, upgrade Nautobot to version 1.6.7 or 2.0.6 or later.

3

What systems are affected by CVE-2023-50263?

CVE-2023-50263 affects Nautobot versions from 1.1.0 to 1.6.6 and from 2.0.0 to 2.0.5.

4

What types of files are impacted by CVE-2023-50263?

CVE-2023-50263 relates to uploaded files associated with run requests for jobs with FileVar inputs.

5

Is CVE-2023-50263 a remote code execution vulnerability?

CVE-2023-50263 does not directly allow remote code execution but can expose sensitive files to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203