OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk lies in potential future modifications to the codebase that might incorrectly rely on the vulnerable internal functions for authentication checks, leading to security vulnerabilities. This issue has been patched in version 1.11.0.
History

Fri, 25 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain frontend pages. The primary risk lies in potential future modifications to the codebase that might incorrectly rely on the vulnerable internal functions for authentication checks, leading to security vulnerabilities. This issue has been patched in version 1.11.0.
Title OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-22T17:14:39.690Z

Updated: 2025-04-25T16:03:30.506Z

Reserved: 2025-04-10T12:51:12.280Z

Link: CVE-2025-32788

cve-icon Vulnrichment

Updated: 2025-04-24T19:56:39.718Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-22T18:15:59.630

Modified: 2025-04-23T14:08:13.383

Link: CVE-2025-32788

cve-icon Redhat

No data.