{"id":"CVE-2024-34707","aliases":["GHSA-r2hr-4v48-fjv3","PYSEC-2026-1688"],"title":"Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages","summary":"Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L","vendor":"nautobot","product":"nautobot","ecosystem":"pip","affected":["nautobot < 1.6.22","nautobot >= 2.0.0, < 2.2.4"],"patched":["nautobot 1.6.22","nautobot 2.2.4"],"published":"2024-05-13","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:14.214530149Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-r2hr-4v48-fjv3","references":[{"url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-r2hr-4v48-fjv3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34707"},{"url":"https://github.com/nautobot/nautobot/pull/5697"},{"url":"https://github.com/nautobot/nautobot/pull/5698"},{"url":"https://github.com/nautobot/nautobot/commit/4f0a66bd6307bfe0e0acb899233e0d4ad516f51c"},{"url":"https://github.com/nautobot/nautobot/commit/f640aedc69c848d3d1be57f0300fc40033ff6423"},{"url":"https://github.com/nautobot/nautobot"}],"tags":["osv","pip"],"epss":0.00606,"epssPercentile":0.47676,"ingestedAt":"2026-07-08T18:25:52.612Z","slug":"CVE-2024-34707","body":"## Overview\n\n### Impact\n\nA Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS).\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nPatches will be released as part of Nautobot 1.6.22 and 2.2.4.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nAs [described in the Nautobot documentation](https://docs.nautobot.com/projects/core/en/stable/user-guide/administration/configuration/optional-settings/#administratively-configurable-settings), these settings are only configurable through the admin UI of Nautobot if they are *not* explicitly set to some non-empty value in the `nautobot_config.py` or equivalent Nautobot configuration file. Therefore, adding the following configuration to said file completely mitigates this vulnerability in both Nautobot 1.x and 2.x:\n\n```python\nBANNER_LOGIN = \" \"\nBANNER_TOP = \" \"\nBANNER_BOTTOM = \" \"\n```\n\nor alternately (Nautobot 2.x only), if those variables are not defined explicitly in your configuration file, setting the following environment variables for the Nautobot user account serves the same purpose:\n\n```shell\nNAUTOBOT_BANNER_LOGIN=\" \"\nNAUTOBOT_BANNER_TOP=\" \"\nNAUTOBOT_BANNER_BOTTOM=\" \"\n```\n\nLimiting all users who do not need elevated privileges to non-admin access (`is_superuser: False` and `is_staff: False`) is a partial mitigation as well.\n\n\n### References\n\n- https://github.com/nautobot/nautobot/pull/5697\n- https://github.com/nautobot/nautobot/pull/5698\n\n## Affected packages\n\n- `nautobot < 1.6.22`\n- `nautobot >= 2.0.0, < 2.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nautobot 1.6.22`\n- `nautobot 2.2.4`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}