CVE-2022-2888: Insufficient Session Expiration in octoprint/octoprint
Published Sep 21, 2022
·Updated
If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to authenticate as long as the victim's account exists.
Affected Software
2 affected componentsFixes available
pip/OctoPrint<1.8.3
1.8.3
OctoPrint OctoPrint<1.8.3
Remediation
Event History
Sep 21, 2022
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
DescriptionSeverityWeakness
Sep 22, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-2888?
CVE-2022-2888 is a vulnerability in OctoPrint that allows an attacker to authenticate using a victim's session cookie.
2
What is the severity of CVE-2022-2888?
CVE-2022-2888 has a severity rating of medium (4.4).
3
How can an attacker exploit CVE-2022-2888?
An attacker can exploit CVE-2022-2888 by obtaining a victim's OctoPrint session cookie and using it to authenticate.
4
Which version of OctoPrint is affected by CVE-2022-2888?
OctoPrint version 1.8.3 and below are affected by CVE-2022-2888.
5
Is there a fix for CVE-2022-2888?
Yes, a fix for CVE-2022-2888 is available. It is recommended to update OctoPrint to a version that includes the fix.