CVE-2022-1432: Cross-site Scripting (XSS) - Generic in octoprint/octoprint
Published May 18, 2022
·Updated
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
Affected Software
2 affected componentsFixes available
pip/OctoPrint<1.8.0
1.8.0
OctoPrint OctoPrint<1.8.0
Remediation
Event History
May 18, 2022
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
May 19, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-1432?
The severity of CVE-2022-1432 is high, with a severity value of 6.4.
2
How does CVE-2022-1432 affect the octoprint/octoprint repository?
CVE-2022-1432 affects the octoprint/octoprint repository prior to version 1.8.0, allowing for Cross-site Scripting (XSS) attacks.
3
What is the CWE ID associated with CVE-2022-1432?
The CWE ID associated with CVE-2022-1432 is CWE-79.
4
How can I fix CVE-2022-1432?
To fix CVE-2022-1432, update the octoprint/octoprint repository to version 1.8.0 or later.
5
Where can I find more information about CVE-2022-1432?
You can find more information about CVE-2022-1432 at the following references: [GitHub Commit](https://github.com/octoprint/octoprint/commit/6d259d7e6f5b0de9a1c762831537a386e53978d3) and [Huntr Bounty](https://huntr.dev/bounties/cb545c63-a3c1-4d57-8f06-e4593ab389bf).