CVE-2024-1222: Incorrect authorization controls in PaperCut NG/MF APIs
This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a small subset of PaperCut NG/MF API calls.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1222?
CVE-2024-1222 has been rated with a significant severity because it allows unauthorized access to elevated API privileges.
How do I fix CVE-2024-1222?
To mitigate CVE-2024-1222, users should update to the latest patched version of PaperCut NG/MF software.
Which versions of PaperCut NG/MF are affected by CVE-2024-1222?
CVE-2024-1222 affects PaperCut NG from version 20.1.10 and various versions up to 23.0.7, as well as PaperCut MF in similar ranges.
What type of attack is enabled by CVE-2024-1222?
CVE-2024-1222 enables attackers to exploit malformed API requests for unauthorized elevated access.
Is there a workaround for CVE-2024-1222 before applying a patch?
No formal workarounds have been provided for CVE-2024-1222; the recommended action is to apply the available updates.