CVE-2024-34707: Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Impact
A Nautobot user with admin privileges can modify the BANNERTOP, BANNERBOTTOM, and BANNERLOGIN configuration settings via the /admin/constance/config/ endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of BANNERLOGIN) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS).
Patches Has the problem been patched? What versions should users upgrade to?
Patches will be released as part of Nautobot 1.6.22 and 2.2.4.
Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading?
As described in the Nautobot documentation, these settings are only configurable through the admin UI of Nautobot if they are not explicitly set to some non-empty value in the nautobotconfig.py or equivalent Nautobot configuration file. Therefore, adding the following configuration to said file completely mitigates this vulnerability in both Nautobot 1.x and 2.x:
python BANNERLOGIN = " " BANNERTOP = " " BANNERBOTTOM = " "
or alternately (Nautobot 2.x only), if those variables are not defined explicitly in your configuration file, setting the following environment variables for the Nautobot user account serves the same purpose:
shell NAUTOBOTBANNERLOGIN=" " NAUTOBOTBANNERTOP=" " NAUTOBOTBANNERBOTTOM=" "
Limiting all users who do not need elevated privileges to non-admin access (issuperuser: False and isstaff: False) is a partial mitigation as well.
References
- https://github.com/nautobot/nautobot/pull/5697 - https://github.com/nautobot/nautobot/pull/5698
Other sources
Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the BANNERTOP, BANNERBOTTOM, and BANNERLOGIN configuration settings via the /admin/constance/config/ endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of BANNERLOGIN) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34707?
CVE-2024-34707 is classified as a high severity vulnerability due to the potential misuse of admin privileges.
How do I fix CVE-2024-34707?
To address CVE-2024-34707, upgrade Nautobot to version 2.2.4 or later, or to version 1.6.22 to mitigate the vulnerability.
Who is affected by CVE-2024-34707?
CVE-2024-34707 affects Nautobot users with admin privileges in versions up to 2.2.4 and 1.6.22.
What are the implications of CVE-2024-34707?
The implication of CVE-2024-34707 is that it allows an admin user to modify site banners, which could be exploited for malicious content.
Where can I find more information about CVE-2024-34707?
More information about CVE-2024-34707 can be found in the Nautobot project's security advisories.