Описание
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
Ссылки
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.3 (исключая)
cpe:2.3:a:octoprint:octoprint:*:*:*:*:*:*:*:*
EPSS
Процентиль: 14%
0.00047
Низкий
4.4 Medium
CVSS3
4.4 Medium
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 4.4
debian
больше 3 лет назад
If an attacker comes into the possession of a victim's OctoPrint sessi ...
CVSS3: 4.4
github
больше 3 лет назад
OctoPrint vulnerable to Insufficient Session Expiration.
EPSS
Процентиль: 14%
0.00047
Низкий
4.4 Medium
CVSS3
4.4 Medium
CVSS3
Дефекты
CWE-613