Executive brief
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
Affected products
- PyPI OctoPrint
Junglewise Threat Intelligence
CVE-2022-2888 · Severity: low · CVSS 3.1 · Published 2022-09-21
Technologies: OctoPrint (PyPI). Vendors: PyPI.
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.