nautobot is vulnerable to Authorization Bypass
64
Medium Risk
Nautobot exposes a generic ApprovalWorkflowStageResponse create endpoint in the REST API that does not enforce the approver checks applied by the stage approve and deny actions. A user holding only the add_approvalworkflowstageresponse permission can POST approved responses directly, attribute them to arbitrary users through the writable user and state fields, and drive a stage past its min_approvers threshold to self-approve a workflow. Because stage approval cascades to enabling the gated ScheduledJob, this escalates into unauthorized activation of scheduled server-side jobs. The fix removes the standalone endpoint and exposes responses only as read-only nested data filtered by view permission.
You are affected if you are using a version that falls within the vulnerable range and you use approval workflows with users who hold the add_approvalworkflowstageresponse permission.
nautobot is vulnerable to Authorization Bypass in versions 3.0.0 - 3.1.7.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant