PT-2024-34657 · Octoprint · Octoprint

Jacopotediosi

·

Published

2024-11-05

·

Updated

2024-12-18

·

CVE-2024-51493

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions up to and including 1.10.2
Description OctoPrint provides a web interface for controlling consumer 3D printers. The issue allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to retrieve, recreate, or delete the user's or the global API key without having to reauthenticate by re-entering the user account's password. An attacker could use a stolen API key to access OctoPrint through its API or disrupt workflows depending on the API key they deleted.
Recommendations For versions up to and including 1.10.2, upgrade to version 1.10.3 to patch the vulnerability. As a temporary workaround, consider restricting access to the API until the issue is resolved. Avoid using the API key in sensitive operations until the upgrade is applied.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-51493
GHSA-CC6X-8CC7-9953
PYSEC-2024-202

Affected Products

Octoprint