PT-2022-19284 · Octoprint · Octoprint

Published

2022-09-21

·

Updated

2022-09-22

·

CVE-2022-2888

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions prior to 1.8.3
Description The issue allows an attacker to authenticate using a victim's OctoPrint session cookie as long as the victim's account exists. This can be done if the attacker comes into possession of the cookie through any means.
Recommendations For versions prior to 1.8.3, update to version 1.8.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of OctoPrint until the update can be applied.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2022-2888
GHSA-937F-QH3W-6G87
PYSEC-2022-282

Affected Products

Octoprint