{"id":"GHSA-75mc-3pjc-727q","summary":"Unauthenticated db-file-storage views","details":"### Impact\n\n In Nautobot 1.x and 2.0.x, the URLs `/files/get/?name=...` and `/files/download/?name=...` are used to provide admin access to files that have been uploaded as part of a run request for a Job that has FileVar inputs. Under normal operation these files are ephemeral and are deleted once the Job in question runs. \n\nIt was reported by @kircheneer that in the default implementation used in Nautobot, as provided by `django-db-file-storage`, these URLs do not by default require any user authentication to access; they should instead be restricted to only users who have permissions to view Nautobot's `FileProxy` model instances.\n\nNote that no URL mechanism is provided for listing or traversal of the available file `name` values, so in practice an unauthenticated user would have to guess names to discover arbitrary files for download, but if a user knows the file name/path value, they can access it without authenticating, so we are considering this a vulnerability.\n\n### Patches\n\nFixes will be included in Nautobot 1.6.7 and Nautobot 2.0.6.\n\n### Workarounds\n\nNo workaround other than applying the patches included in https://github.com/nautobot/nautobot/pull/4959/files (2.0.x) or https://github.com/nautobot/nautobot/pull/4964/files (1.6.x)\n\n### References\n\n- https://github.com/victor-o-silva/db_file_storage/blob/master/db_file_storage/views.py","aliases":["CVE-2023-50263","PYSEC-2023-286"],"modified":"2026-09-10T03:49:59.415839617Z","published":"2023-12-13T13:35:48Z","database_specific":{"nvd_published_at":"2023-12-12T23:15:07Z","cwe_ids":["CWE-200","CWE-306"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-12-13T13:35:48Z"},"references":[{"type":"WEB","url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-75mc-3pjc-727q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50263"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/pull/4959"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/pull/4964"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/commit/458280c359a4833a20da294eaf4b8d55edc91cee"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/commit/5e2ba9e8ac0840b1c44eb1a8ea3c0bd2c68e4f80"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/commit/7c4cf3137f45f1541f09f2f6a7f8850cd3a2eaee"},{"type":"PACKAGE","url":"https://github.com/nautobot/nautobot"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nautobot/PYSEC-2023-286.yaml"},{"type":"WEB","url":"https://github.com/victor-o-silva/db_file_storage/blob/master/db_file_storage/views.py"}],"affected":[{"package":{"name":"nautobot","ecosystem":"PyPI","purl":"pkg:pypi/nautobot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0"},{"fixed":"1.6.7"}]}],"versions":["1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.2.1","1.2.10","1.2.11","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.10","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.10","1.4.2","1.4.3","1.4.4","1.4.5","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.16","1.5.17","1.5.18","1.5.19","1.5.2","1.5.20","1.5.21","1.5.22","1.5.23","1.5.24","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-75mc-3pjc-727q/GHSA-75mc-3pjc-727q.json"}},{"package":{"name":"nautobot","ecosystem":"PyPI","purl":"pkg:pypi/nautobot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.6"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-75mc-3pjc-727q/GHSA-75mc-3pjc-727q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}