nautobot is vulnerable to Privilege Escalation
35
Low Risk
Nautobot gates Job execution behind the run permission, but the Job Hook dispatch path does not check it. A user who can manage Job Hooks but lacks the run permission can point a hook at a JobHookReceiver and trigger it by editing a matching object, causing the receiver code to run on the worker. This allows execution of job code the user is not authorized to run. The fix enforces the run permission on the Job Hook dispatch path, skipping dispatch when the responsible user lacks it.
You are affected if you are using a version that falls within the vulnerable range and you grant users permission to manage Job Hooks without granting them the run permission.
nautobot is vulnerable to Privilege Escalation in versions 0.0.1 - 2.4.37 and 3.0.0 - 3.1.8.
Upgrade the nautobot library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant