CVE-2022-2930: Unverified Password Change in octoprint/octoprint
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
Other sources
Versions of OctoPrint prior to 1.8.3 did not require the current user password in order to change that users password. As a result users could be locked out of their accounts or have their accounts stolen under certain circumstances.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2930?
The severity of CVE-2022-2930 is high with a CVSS score of 7.8.
How does CVE-2022-2930 affect Octoprint?
CVE-2022-2930 affects Octoprint versions prior to 1.8.3.
How can I fix the unverified password change vulnerability in Octoprint?
To fix the unverified password change vulnerability in Octoprint, update to version 1.8.3 or later.
Where can I find more information about CVE-2022-2930?
You can find more information about CVE-2022-2930 on the following links: [GitHub Commit](https://github.com/octoprint/octoprint/commit/1453076ee3e47fcab2dc73664ec2d61d3ef7fc4f) and [Huntr Bounty](https://huntr.dev/bounties/da6745e4-7bcc-4e9a-9e96-0709ec9f2477).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-2930?
The Common Weakness Enumeration (CWE) ID for CVE-2022-2930 is CWE-620.