Vulnerability Details CVE-2023-51649
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level `extras.run_job` permission is checked (i.e., does the user have permission to run Jobs in general). Object-level permissions (i.e., does the user have permission to run this specific Job?) are not enforced by the URL/view used in this case. A user with permissions to run even a single Job can actually run all configured JobButton Jobs. Fix will be available in Nautobot 1.6.8 and 2.1.0
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.0%
CVSS Severity
CVSS v3 Score 3.5
Products affected by CVE-2023-51649
-
cpe:2.3:a:networktocode:nautobot:1.5.14
-
cpe:2.3:a:networktocode:nautobot:1.5.15
-
cpe:2.3:a:networktocode:nautobot:1.5.16
-
cpe:2.3:a:networktocode:nautobot:1.5.17
-
cpe:2.3:a:networktocode:nautobot:1.5.18
-
cpe:2.3:a:networktocode:nautobot:1.5.19
-
cpe:2.3:a:networktocode:nautobot:1.5.20
-
cpe:2.3:a:networktocode:nautobot:1.5.21
-
cpe:2.3:a:networktocode:nautobot:1.5.22
-
cpe:2.3:a:networktocode:nautobot:1.5.23
-
cpe:2.3:a:networktocode:nautobot:1.5.24
-
cpe:2.3:a:networktocode:nautobot:1.6.0
-
cpe:2.3:a:networktocode:nautobot:1.6.1
-
cpe:2.3:a:networktocode:nautobot:1.6.2
-
cpe:2.3:a:networktocode:nautobot:1.6.3
-
cpe:2.3:a:networktocode:nautobot:1.6.4
-
cpe:2.3:a:networktocode:nautobot:1.6.5
-
cpe:2.3:a:networktocode:nautobot:1.6.6
-
cpe:2.3:a:networktocode:nautobot:1.6.7
-
cpe:2.3:a:networktocode:nautobot:2.0.0
-
cpe:2.3:a:networktocode:nautobot:2.0.1
-
cpe:2.3:a:networktocode:nautobot:2.0.2
-
cpe:2.3:a:networktocode:nautobot:2.0.3
-
cpe:2.3:a:networktocode:nautobot:2.0.4
-
cpe:2.3:a:networktocode:nautobot:2.0.5
-
cpe:2.3:a:networktocode:nautobot:2.0.6