GHSA-49wm-4fp6-h59c
Dashboard / Vulnerabilities / GHSA-49wm-4fp6-h59c
GHSA-49wm-4fp6-h59c
Summary: OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type
Details: OctoPrint prior to version 1.8.3 is vulnerable to Unrestricted Upload of File with Dangerous Type. Due to misconfiguration in move file functionality, an attacker could easily change the file extension of an uploaded malicious file disguised as a `.gcode` file. Version 1.8.3 contains a patch.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-2872, https://github.com/octoprint/octoprint/commit/3e3c11811e216fb371a33e28412df83f9701e5b0, https://github.com/octoprint/octoprint, https://github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2022-286.yaml, https://huntr.dev/bounties/b966c74d-6f3f-49fe-b40a-eaf25e362c56
Affected packages
Package
Name: octoprint
Purl: pkg:pypi/octoprint
Affected ranges
Type: ECOSYSTEM
Events:
