Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.4
CVE-2022-1432
- EPSS 1.21%
- Veröffentlicht 18.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:43
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
7.5
CVE-2022-1430
- EPSS 1.34%
- Veröffentlicht 18.05.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:43
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
6.1
CVE-2021-32561
- EPSS 1.15%
- Veröffentlicht 11.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:16
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
6.5
CVE-2021-32560
- EPSS 1.5%
- Veröffentlicht 11.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:16
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
9.1
CVE-2018-16710
- EPSS 2.09%
- Veröffentlicht 07.09.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:53:12
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind...