Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 PyPI

Unverified Password Change in OctoPrint

GHSA-39gf-864w-pxw4 · CVE-2022-2930 · PYSEC-2022-43142

Published · Modified

Description

Versions of OctoPrint prior to 1.8.3 did not require the current user password in order to change that users password. As a result users could be locked out of their accounts or have their accounts stolen under certain circumstances.

Ready to move

Start Securing

Free, no credit card | First findings in minutes