CVE-2024-36112
Last modified
CVE-2024-36112 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-groups/<uuid>/members/`) to list the objects that are members of a given Dynamic Group. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or the members REST API view (`/api/extras/dynamic-groups/<uuid>/members/`) to list the objects that are members of a given Dynamic Group. In versions of Nautobot between 1.3.0 (where the Dynamic Groups feature was added) and 1.6.22 inclusive, and 2.0.0 through 2.2.4 inclusive, Nautobot fails to restrict these listings based on the member object permissions - for example a Dynamic Group of Device objects will list all Devices that it contains, regardless of the user's `dcim.view_device` permissions or lack thereof. This issue has been fixed in Nautobot versions 1.6.23 and 2.2.5. Users are advised to upgrade. This vulnerability can be partially mitigated by removing `extras.view_dynamicgroup` permission from users however a full fix will require upgrading.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Networktocode | Nautobot | >= 1.3.0, < 1.6.23 |
| Networktocode | Nautobot | >= 2.0.0, <= 2.2.5 |
References
- https://github.com/nautobot/nautobot/security/advisories/GHSA-qmjf-wc2h-6x3qThird Party Advisory
- https://github.com/nautobot/nautobot/security/advisories/GHSA-qmjf-wc2h-6x3qThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-36112?
How severe is CVE-2024-36112?
How do I fix CVE-2024-36112?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-36107MinIO is a High Performance Object Storage released under GN…5.3
- CVE-2024-36108casgate is an Open Source Identity and Access Management sys…9.8
- CVE-2024-36109CoCalc is web-based software that enables collaboration in r…7.6
- CVE-2024-3611The Toolbar Extras for Elementor & More – WordPress Admin Ba…6.4
- CVE-2024-36110ansibleguy-webui is an open source WebUI for using Ansible. …8.2
- CVE-2024-36111KubePi is a K8s panel. Starting in version 1.6.3 and prior t…6.3
- CVE-2024-36113Discourse is an open-source discussion platform. Prior to ve…6.5
- CVE-2024-36114Aircompressor is a library with ports of the Snappy, LZO, LZ…8.6
- CVE-2024-36115Reposilite is an open source, lightweight and easy-to-use re…7.1
- CVE-2024-36116Reposilite is an open source, lightweight and easy-to-use re…9.8
- CVE-2024-36117Reposilite is an open source, lightweight and easy-to-use re…7.5
- CVE-2024-36118MeterSphere is a test management and interface testing tool.…4.3
Are you affected by CVE-2024-36112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
