SCA: security update for OctoPrint (GHSA-x7mf-wrh9-r76c)

medium Tenable Self-Hosted Container Security Plugin ID 420361

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and
including 1.9.3 contain a vulnerability that allows malicious admins to configure or talk a victim with
administrator rights into configuring a webcam snapshot URL which when tested through the "Test" button
included in the web interface will execute JavaScript code in the victims browser when attempting to
render the snapshot image. An attacker who successfully talked a victim with admin rights into performing
a snapshot test with such a crafted URL could use this to retrieve or modify sensitive configuration
settings, interrupt prints or otherwise interact with the OctoPrint instance in a malicious way. The
vulnerability is patched in version 1.10.0rc3. OctoPrint administrators are strongly advised to thoroughly
vet who has admin access to their installation and what settings they modify based on instructions by
strangers. (CVE-2024-28237)

See Also

https://github.com/advisories/GHSA-x7mf-wrh9-r76c

Plugin Details

Severity: Medium

ID: 420361

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.14

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N

CVSS Score Source: CVE-2024-28237

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/18/2024

Vulnerability Publication Date: 3/18/2024

Reference Information

CVE: CVE-2024-28237

cwe: CWE-79