CVE-2024-32977
- EPSS 0.9%
- Veröffentlicht 14.05.2024 16:17:12
- Zuletzt bearbeitet 10.04.2025 20:33:40
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` ...
CVE-2024-28237
- EPSS 0.44%
- Veröffentlicht 18.03.2024 22:15:07
- Zuletzt bearbeitet 08.01.2025 16:22:58
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to configure or talk a victim with administrator rights into configuring a w...
CVE-2024-23637
- EPSS 0.52%
- Veröffentlicht 31.01.2024 18:15:49
- Zuletzt bearbeitet 21.11.2024 08:58:03
OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious admins to change the password of other admin accounts, including their own, without having to repeat their pas...
CVE-2023-41047
- EPSS 0.57%
- Veröffentlicht 09.10.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:27
OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted GCODE script that will allow code execution during rendering of that s...
- EPSS 0.42%
- Veröffentlicht 19.10.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 07:19:52
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-3068
- EPSS 0.46%
- Veröffentlicht 21.09.2022 12:15:10
- Zuletzt bearbeitet 21.11.2024 07:18:45
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-2888
- EPSS 0.29%
- Veröffentlicht 21.09.2022 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:52
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
CVE-2022-2872
- EPSS 0.57%
- Veröffentlicht 21.09.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:50
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-2930
- EPSS 0.35%
- Veröffentlicht 22.08.2022 12:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:56
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-2822
- EPSS 0.82%
- Veröffentlicht 15.08.2022 11:21:32
- Zuletzt bearbeitet 21.11.2024 07:01:45
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.