PT-2022-4444 · Octoprint · Octoprint

Published

2022-08-20

·

Updated

2022-08-23

·

CVE-2022-2930

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OctoPrint versions prior to 1.8.3
Description The issue is related to unverified password change in OctoPrint, which is associated with insecure privilege management. This allows an attacker to change a user's account password without knowing the current password, potentially leading to account lockout or theft under certain circumstances.
Recommendations For versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the password change functionality until the update is applied.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05309
CVE-2022-2930
GHSA-39GF-864W-PXW4
PYSEC-2022-43142

Affected Products

Octoprint