CVE-2022-2872

LOW3.7EPSS 0.22%

OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

發布日:2022/9/22修改日:2024/10/7
也稱為:GHSA-49wm-4fp6-h59cPYSEC-2022-286

描述

OctoPrint prior to version 1.8.3 is vulnerable to Unrestricted Upload of File with Dangerous Type. Due to misconfiguration in move file functionality, an attacker could easily change the file extension of an uploaded malicious file disguised as a `.gcode` file. Version 1.8.3 contains a patch.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1LOW3.7CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

參考連結(5)