CVE-2024-34707: Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Published May 13, 2024
·
Updated

Impact

A Nautobot user with admin privileges can modify the BANNERTOP, BANNERBOTTOM, and BANNERLOGIN configuration settings via the /admin/constance/config/ endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of BANNERLOGIN) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS).

Patches Has the problem been patched? What versions should users upgrade to?

Patches will be released as part of Nautobot 1.6.22 and 2.2.4.

Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading?

As described in the Nautobot documentation, these settings are only configurable through the admin UI of Nautobot if they are not explicitly set to some non-empty value in the nautobotconfig.py or equivalent Nautobot configuration file. Therefore, adding the following configuration to said file completely mitigates this vulnerability in both Nautobot 1.x and 2.x:

python BANNERLOGIN = " " BANNERTOP = " " BANNERBOTTOM = " "

or alternately (Nautobot 2.x only), if those variables are not defined explicitly in your configuration file, setting the following environment variables for the Nautobot user account serves the same purpose:

shell NAUTOBOTBANNERLOGIN=" " NAUTOBOTBANNERTOP=" " NAUTOBOTBANNERBOTTOM=" "

Limiting all users who do not need elevated privileges to non-admin access (issuperuser: False and isstaff: False) is a partial mitigation as well.

References

- https://github.com/nautobot/nautobot/pull/5697 - https://github.com/nautobot/nautobot/pull/5698

Other sources

Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the BANNERTOP, BANNERBOTTOM, and BANNERLOGIN configuration settings via the /admin/constance/config/ endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of BANNERLOGIN) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.

MITRE

Affected Software

4 affected componentsFixes available
pip/nautobot>=2.0.0<2.2.4
2.2.4
pip/nautobot<1.6.22
1.6.22
Networktocode Nautobot<1.6.22
Networktocode Nautobot>=2.0.0<2.2.4

Event History

May 13, 2024
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·07:59 PM
May 14, 2024
Data Sourced
via NVD·03:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:39 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-34707?

CVE-2024-34707 is classified as a high severity vulnerability due to the potential misuse of admin privileges.

2

How do I fix CVE-2024-34707?

To address CVE-2024-34707, upgrade Nautobot to version 2.2.4 or later, or to version 1.6.22 to mitigate the vulnerability.

3

Who is affected by CVE-2024-34707?

CVE-2024-34707 affects Nautobot users with admin privileges in versions up to 2.2.4 and 1.6.22.

4

What are the implications of CVE-2024-34707?

The implication of CVE-2024-34707 is that it allows an admin user to modify site banners, which could be exploited for malicious content.

5

Where can I find more information about CVE-2024-34707?

More information about CVE-2024-34707 can be found in the Nautobot project's security advisories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203