PT-2025-24685 · Jinja2+1 · Jinja2+1
Mzbroch
·
Published
2025-06-10
·
Updated
2025-08-21
·
CVE-2025-49142
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nautobot versions prior to 1.6.32
Nautobot versions prior to 2.4.10
Description
The issue arises from insufficient security configuration of the Jinja2 templating feature in Nautobot, which can be exploited by a malicious user to expose Secrets or modify data within Nautobot by bypassing object permissions. This can occur when templated content is rendered.
Recommendations
For versions prior to 1.6.32, update to version 1.6.32 or later to resolve the issue.
For versions prior to 2.4.10, update to version 2.4.10 or later to resolve the issue.
As a temporary workaround, consider configuring object permissions to limit certain actions to only trusted users, which can partially mitigate the vulnerability.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jinja2
Nautobot