{"id":"CVE-2024-23345","aliases":["GHSA-v4xv-795h-rv4h","PYSEC-2024-16"],"title":"XSS potential in rendered Markdown fields (comments, description, notes, etc.)","summary":"XSS potential in rendered Markdown fields (comments, description, notes, etc.)","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L","vendor":"nautobot","product":"nautobot","ecosystem":"pip","affected":["nautobot >= 2.0.0, < 2.1.2","nautobot < 1.6.10"],"patched":["nautobot 2.1.2","nautobot 1.6.10"],"published":"2024-01-23","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:09.620510398Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v4xv-795h-rv4h","references":[{"url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-v4xv-795h-rv4h"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-23345"},{"url":"https://github.com/nautobot/nautobot/pull/5133"},{"url":"https://github.com/nautobot/nautobot/pull/5134"},{"url":"https://github.com/nautobot/nautobot/commit/17effcbe84a72150c82b138565c311bbee357e80"},{"url":"https://github.com/nautobot/nautobot/commit/64312a4297b5ca49b6cdedf477e41e8e4fd61cce"},{"url":"https://github.com/nautobot/nautobot"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2024-16.yaml"}],"tags":["osv","pip"],"epss":0.00433,"epssPercentile":0.37107,"ingestedAt":"2026-09-12T03:13:01.729Z","slug":"CVE-2024-23345","body":"## Overview\n\n### Impact\n\nAll users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted.\n\nDue to inadequate input sanitization, any user-editable fields that support Markdown rendering, including:\n\n- `Circuit.comments`\n- `Cluster.comments`\n- `CustomField.description`\n- `Device.comments`\n- `DeviceRedundancyGroup.comments`\n- `DeviceType.comments`\n- `Job.description`\n- `JobLogEntry.message`\n- `Location.comments`\n- `Note.note`\n- `PowerFeed.comments`\n- `Provider.noc_contact`\n- `Provider.admin_contact`\n- `Provider.comments`\n- `ProviderNetwork.comments`\n- `Rack.comments`\n- `Tenant.comments`\n- `VirtualMachine.comments`\n- Contents of any custom fields of type `markdown`\n- Job class `description` attributes\n- The `SUPPORT_MESSAGE` system configuration setting\n\nare potentially susceptible to cross-site scripting (XSS) attacks via maliciously crafted data.\n\n### Patches\n\nFixed in Nautobot versions 1.6.10 and 2.1.2.\n\n### References\n\nhttps://github.com/nautobot/nautobot/pull/5133\nhttps://github.com/nautobot/nautobot/pull/5134\n\n\n## Affected packages\n\n- `nautobot >= 2.0.0, < 2.1.2`\n- `nautobot < 1.6.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nautobot 2.1.2`\n- `nautobot 1.6.10`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}