4.4

CVE-2022-2888

Exploit

Insufficient Session Expiration in octoprint/octoprint

If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OctoprintOctoprint Version < 1.8.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.191
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 1.8 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
security@huntr.dev 4.4 1.8 2.5
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

https://github.com/octoprint/octoprint/commit/40e6217ac1a85cc5ed592873ae49db01d3005da4
Patch
Third Party Advisory
https://huntr.dev/bounties/d27d232b-2578-4b32-b3b4-74aabdadf629
Patch
Third Party Advisory
Exploit