MEDIUM
OctoPrint Unverified Password Change via Access Control Settings
Published Jan 31, 2024
4.9
MEDIUMCVSS 3.1
EPSS 0.52%
Description
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their password. An attacker who managed to hijack an admin account might use this to lock out actual admins from their OctoPrint instance. The vulnerability will be patched in version 1.10.0.
Affected products
-
Affected
- < 1.10.0rc1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0120 Advisory
- https://github.com/OctoPrint/OctoPrint/commit/1729d167b4ae4a5835bbc7211b92c6828b1c4125 x_refsource_MISCPatch
- https://github.com/OctoPrint/OctoPrint/releases/tag/1.10.0rc1 x_refsource_MISCRelease Notes
- https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjr x_refsource_CONFIRMThird Party Advisory
- https://github.com/advisories/GHSA-5626-pw9c-hmjr Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2024-29.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2024-23637
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0120 | Advisory | |
| https://github.com/OctoPrint/OctoPrint/commit/1729d167b4ae4a5835bbc7211b92c6828b1c4125 | x_refsource_MISCPatch | |
| https://github.com/OctoPrint/OctoPrint/releases/tag/1.10.0rc1 | x_refsource_MISCRelease Notes | |
| https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-5626-pw9c-hmjr | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/advisories/GHSA-5626-pw9c-hmjr | Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2024-29.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-23637 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 31, 2024
Updated Jun 17, 2025
Reserved Jan 19, 2024
Link CVE-2024-23637
CISA Vulnrichment
Updated Feb 8, 2024
Red Hat
No data
GitHub
Link GHSA-5626-PW9C-HMJR