CVE-2021-32560: Medium severity octoprint vulnerability
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not .log files.
Other sources
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not .log files.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32560?
CVE-2021-32560 is a vulnerability in OctoPrint before 1.6.0 that has incorrect access control in its Logging subsystem.
How severe is CVE-2021-32560?
CVE-2021-32560 has a severity rating of 6.5, which is considered medium severity.
What is affected by CVE-2021-32560?
OctoPrint versions before 1.6.0 are affected by CVE-2021-32560.
How can I fix CVE-2021-32560?
To fix CVE-2021-32560, upgrade to OctoPrint version 1.6.0 or later.
Where can I find more information about CVE-2021-32560?
More information about CVE-2021-32560 can be found in the references: [GitHub](https://github.com/OctoPrint/OctoPrint/releases/tag/1.6.0), [OctoPrint Blog](https://octoprint.org/blog/2021/04/27/new-release-1.6.0/), [Brzozowski.io](https://www.brzozowski.io/web-applications/2021/05/11/the-insecure-story-of-octoprint.html).