Password change without identity check In octoprint
Description
Unverified Password Change in OctoPrint Versions of OctoPrint prior to 1.8.3 did not require the current user password in order to change that users password. As a result users could be locked out of their accounts or have their accounts stolen under certain circumstances.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 1.8.3 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.