Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-39gf-864w-pxw4: Unverified Password Change in OctoPrint

Versions of OctoPrint prior to 1.8.3 did not require the current user password in order to change that users password. As a result users could be locked out of their accounts or have their accounts stolen under certain circumstances.

ghsa
#git

Unverified Password Change in OctoPrint

Moderate severity GitHub Reviewed Published Aug 23, 2022 • Updated Aug 30, 2022

Related news

CVE-2022-2930

Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.