PT-2026-105860 · Pypi · Nautobot
Publicado
2026-10-01
·
Atualizado
2026-10-01
CVSS v3.1
6.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Impact
This is an authorization bypass that escalates into unauthorized server-side job execution.
-
Primary impact - self-approval: The approver checks (approver-group membership,
changepermission on the object under review, one-response-per-user) are enforced only in theapprove/denyactions onApprovalWorkflowStage. The genericApprovalWorkflowStageResponsecreate endpoint enforces none of them, so a user holding onlyextras.add approvalworkflowstageresponsecanPOSTapproved responses directly and drive a stage past itsmin approversthreshold with no legitimate approver involved. The serializer also exposesuserandstateas writable, letting the attacker attribute responses to arbitrary users. -
Escalated impact job activation: Because the approval workflow gates a
ScheduledJob, self-approval does not stop at the approval record. Stage approval cascades throughApprovalWorkflow.save()toon workflow approved(), which sets the target job to enabled/active.
Patches
Fixed in Nautobot v3.1.8
Workarounds
Restrict the
extras.add approvalworkflowstageresponse permission so that no untrusted user holds it; approval responses should only ever be created via the stage approve/deny actions. There is no configuration flag that disables the generic create endpoint prior to the patch.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nautobot