id: PYSEC-2022-283 details: Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3. affected: - package: name: octoprint ecosystem: PyPI purl: pkg:pypi/octoprint ranges: - type: GIT repo: https://github.com/octoprint/octoprint events: - introduced: "0" - fixed: ef95ef1c101b79394f134e8fce000e6bae046571 - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.8.3 versions: - 1.3.11 - 1.3.12 - 1.3.12rc1 - 1.3.12rc3 - 1.4.0 - 1.4.0rc1 - 1.4.0rc2 - 1.4.0rc3 - 1.4.0rc4 - 1.4.0rc5 - 1.4.0rc6 - 1.4.1 - 1.4.1rc1 - 1.4.1rc2 - 1.4.1rc3 - 1.4.1rc4 - 1.4.2 - 1.5.0 - 1.5.0rc1 - 1.5.0rc2 - 1.5.0rc3 - 1.5.1 - 1.5.2 - 1.5.3 - 1.6.0 - 1.6.0rc1 - 1.6.0rc2 - 1.6.0rc3 - 1.6.1 - 1.7.0 - 1.7.0rc1 - 1.7.0rc2 - 1.7.0rc3 - 1.7.1 - 1.7.2 - 1.7.3 - 1.8.0 - 1.8.0rc1 - 1.8.0rc2 - 1.8.0rc3 - 1.8.0rc4 - 1.8.0rc5 - 1.8.1 - 1.8.2 references: - type: WEB url: https://huntr.dev/bounties/f45c24cb-9104-4c6e-a9e1-5c7e75e83884 - type: FIX url: https://github.com/octoprint/octoprint/commit/ef95ef1c101b79394f134e8fce000e6bae046571 - type: ADVISORY url: https://github.com/advisories/GHSA-2p75-q37p-f852 aliases: - CVE-2022-3068 - GHSA-2p75-q37p-f852 modified: "2022-09-22T17:04:30.556436Z" published: "2022-09-21T12:15:00Z"