{"id":"GHSA-cc6x-8cc7-9953","summary":"OctoPrint has API key access in settings without reauthentication","details":"### Impact\n\nOctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to retrieve/recreate/delete the user's or - if the victim has admin permissions - the global API key without having to reauthenticate by re-entering the user account's password. \n\nAn attacker could use a stolen API key to access OctoPrint through its API, or disrupt workflows depending on the API key they deleted.\n\n### Patches\n\nThe vulnerability will be patched in version 1.10.3.\n\n### Credits\n\nThis vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi.","aliases":["CVE-2024-51493","PYSEC-2024-202"],"modified":"2025-01-21T18:19:59.517461Z","published":"2024-11-05T15:08:57Z","database_specific":{"nvd_published_at":"2024-11-05T19:15:07Z","cwe_ids":["CWE-306","CWE-620"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-11-05T15:08:57Z"},"references":[{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-cc6x-8cc7-9953"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-51493"},{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/commit/9bc80d782d72881b16e20873dcd0b8314324c70c"},{"type":"PACKAGE","url":"https://github.com/OctoPrint/OctoPrint"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2024-202.yaml"}],"affected":[{"package":{"name":"octoprint","ecosystem":"PyPI","purl":"pkg:pypi/octoprint"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.3"}]}],"versions":["1.10.0","1.10.0rc1","1.10.0rc2","1.10.0rc3","1.10.0rc4","1.10.1","1.10.2","1.3.11","1.3.12","1.3.12rc1","1.3.12rc3","1.4.0","1.4.0rc1","1.4.0rc2","1.4.0rc3","1.4.0rc4","1.4.0rc5","1.4.0rc6","1.4.1","1.4.1rc1","1.4.1rc2","1.4.1rc3","1.4.1rc4","1.4.2","1.5.0","1.5.0rc1","1.5.0rc2","1.5.0rc3","1.5.1","1.5.2","1.5.3","1.6.0","1.6.0rc1","1.6.0rc2","1.6.0rc3","1.6.1","1.7.0","1.7.0rc1","1.7.0rc2","1.7.0rc3","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.9.0","1.9.0rc1","1.9.0rc2","1.9.0rc3","1.9.0rc4","1.9.0rc5","1.9.0rc6","1.9.1","1.9.2","1.9.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.10.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-cc6x-8cc7-9953/GHSA-cc6x-8cc7-9953.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}