CVE-2018-16710: Infoleak
DISPUTED OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting OctoPrint onto the public internet is a terrible idea, and I really can't emphasize that enough."
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16710?
CVE-2018-16710 is a vulnerability in OctoPrint through version 1.3.9 that allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081.
What is the severity of CVE-2018-16710?
The severity of CVE-2018-16710 is critical with a CVSS score of 9.1.
How can I exploit CVE-2018-16710?
We do not provide information on how to exploit vulnerabilities. It is important to follow ethical guidelines and adhere to the law.
How do I fix CVE-2018-16710?
To fix CVE-2018-16710, it is recommended to upgrade OctoPrint to a version beyond 1.3.9.
Where can I find more information about CVE-2018-16710?
You can find more information about CVE-2018-16710 at the following reference: [https://github.com/foosel/OctoPrint/issues/2814]