CVE-2024-23637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
31/01/2024
Last modified:
08/02/2024

Description

OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance. The vulnerability will be patched in version 1.10.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octoprint:octoprint:*:*:*:*:*:*:*:* 1.9.3 (including)