CVE-2024-23637
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their…
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance. The vulnerability will be patched in version 1.10.0.
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287, CWE-620
- Affected
- octoprint/octoprint
- Source
- security-advisories@github.com
References
- https://github.com/OctoPrint/OctoPrint/commit/1729d167b4ae4a5835bbc7211b92c6828b1c4125Patch
- https://github.com/OctoPrint/OctoPrint/releases/tag/1.10.0rc1Release Notes
- https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjrThird Party Advisory
- https://github.com/OctoPrint/OctoPrint/commit/1729d167b4ae4a5835bbc7211b92c6828b1c4125Patch
- https://github.com/OctoPrint/OctoPrint/releases/tag/1.10.0rc1Release Notes
- https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjrThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.