Junglewise Threat Intelligence

CVE-2024-32977: PYSEC-2024-237 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerab

CVE-2024-32977 · Severity: low · CVSS 3.1 · Published 2024-05-14

Technologies: OctoPrint (PyPI), OctoPrint. Vendors: PyPI, OctoPrint.

Executive brief

OctoPrint is a popular open-source web interface for 3D printer control and monitoring. When the autologinLocal feature is enabled, attackers can bypass authentication entirely by spoofing their IP address through the X-Forwarded-For header, gaining unauthorized access to printer management and control functions without requiring valid credentials.

Technical details

This is an authentication bypass vulnerability (CWE-290: Authentication Bypass by Spoofing) in OctoPrint's IP-based local network detection logic. When autologinLocal is enabled in config.yaml, the application trusts the X-Forwarded-For HTTP header to determine if a request originates from a local network, allowing automatic login without credentials. An unauthenticated attacker can spoof this header (e.g., set X-Forwarded-For: 127.0.0.1) to trick the application into auto-logging them in as a configured user. The attack requires network access to the OctoPrint instance and the autologinLocal feature to be explicitly enabled; the vulnerability is network-adjacent in attack vector and does not require user interaction. The fix has been released in version 1.10.1.

Affected products

  • OctoPrint OctoPrint up to and including 1.10.0

Timeline

  • 2024-05-14: disclosed
  • 2024-05-14: patched: Fixed in version 1.10.1

References

Related threats