SB2024053188 - Multiple vulnerabilities in Nautobot
Published: May 31, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Security features bypass (CVE-ID: CVE-2024-35195)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to the session object does not verify requests after making first request with verify=False. A local administrator can bypass authentication.
2) Information disclosure (CVE-ID: CVE-2024-36112)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to dynamic-group-members UI and REST API does not enforce permission restrictions on member objects. A remote user can gain unauthorized access to sensitive information on the system.
Remediation
Install update from vendor's website.
References
- https://github.com/nautobot/nautobot/releases/tag/v2.2.5"
- https://github.com/nautobot/nautobot/releases/tag/v2.2.5</a></p><p>
- https://github.com/nautobot/nautobot/releases/tag/v1.6.23</p><p><br></p>
- https://github.com/nautobot/nautobot/releases/tag/v2.2.5
- https://github.com/nautobot/nautobot/releases/tag/v1.6.23