#VU100038 Missing Authentication for Critical Function in OctoPrint - CVE-2024-51493
Published: November 7, 2024
OctoPrint
octoprint.org
Description
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to a missing additional authorization step when performing sensitive actions, such as managing the API keys. A remote attacker who gained temporary control over an authenticated victim's OctoPrint browser session can retrieve, recreate, or delete the user's API key.