CVE-2024-34707

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
14/05/2024
Last modified:
26/08/2025

Description

Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* 1.6.22 (excluding)
cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* 2.0.0 (including) 2.2.4 (excluding)