CVE-2024-23345 - CVE House
Back to Database
Status published High CVE-2024-23345

Nautobot has XSS potential in rendered Markdown fields

Vulnerability Description

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input sanitization, any user-editable fields that support Markdown rendering, including are potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data. This issue is fixed in Nautobot versions 1.6.10 and 2.1.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23345

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nautobot
Vulnerable Versions:
>= 2.0.0, < 2.1.2, < 1.6.10

Timeline

Official Publish: January 22nd, 2024
Last Modified: May 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

Weaknesses (CWE)