Nautobot vulnerable to Reflected Cross-Site Scripting (Reflected XSS) attack
CVE-2024-32979
What is CVE-2024-32979?
The vulnerability in Nautobot arises from improper handling and escaping of user-provided query parameters. This issue allows attackers to craft a malicious Nautobot URL that can execute reflected cross-site scripting (XSS) attacks on unsuspecting users. All filterable object-list views in Nautobot are susceptible to this vulnerability. To address the issue, updates have been released in Nautobot versions 1.6.20 and 2.2.3, with no workarounds available for those using affected versions. Users are strongly advised to upgrade their installations to the latest versions to safeguard against potential XSS exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nautobot < 1.6.20 < 1.6.20
nautobot >= 2.0.0, < 2.2.3 < 2.0.0, 2.2.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
