CVE-2023-51649 - CVE House
Back to Database
Status published Low CVE-2023-51649

Nautobot missing object-level permissions enforcement when running Job Buttons

Vulnerability Description

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level `extras.run_job` permission is checked (i.e., does the user have permission to run Jobs in general). Object-level permissions (i.e., does the user have permission to run this specific Job?) are not enforced by the URL/view used in this case. A user with permissions to run even a single Job can actually run all configured JobButton Jobs. Fix will be available in Nautobot 1.6.8 and 2.1.0

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-51649

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nautobot
Vulnerable Versions:
>= 1.5.14, < 1.6.8, >= 2.0.0, < 2.1.0

Timeline

Official Publish: December 22nd, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L

Weaknesses (CWE)