Junglewise Threat Intelligence

CVE-2022-2930: PYSEC-2022-43142 - Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

CVE-2022-2930 · Severity: low · CVSS 3.1 · Published 2022-08-22

Technologies: OctoPrint (PyPI), OctoPrint. Vendors: PyPI, OctoPrint.

Executive brief

OctoPrint is a web-based interface for managing 3D printers. Prior to version 1.8.3, the password change function did not require users to verify their current password, allowing attackers with local access or session hijacking capabilities to lock legitimate users out of their accounts or take them over entirely.

Technical details

The vulnerability is an improper access control flaw (CWE-620) in OctoPrint's password change endpoint. Versions before 1.8.3 failed to require verification of the current password when a user changed their own password. An attacker with local access to an unlocked session, or via CSRF/session compromise, could change a user's password without providing the original password, leading to account lockout or takeover. The fix, applied in version 1.8.3, mandates that users without the SETTINGS permission must provide their current password to change it. Administrators retain the ability to reset user passwords without the current password.

Affected products

  • OctoPrint OctoPrint before 1.8.3

Timeline

  • 2022-08-23: disclosed
  • 2022-08-22: patched: Fix committed to dev branch

References

Related threats