Access Control Flaw in OctoPrint Logging System by OctoPrint
CVE-2021-32560

6.5MEDIUM

Key Information:

Vendor

Octoprint

Status
Vendor
CVE Published:
11 May 2021

What is CVE-2021-32560?

The logging subsystem in OctoPrint prior to version 1.6.0 contains an access control vulnerability that inadequately manages file access, allowing operations on files beyond just *.log files. This misconfiguration could potentially expose sensitive information or allow unauthorized actions, posing a risk to the integrity of the application's logging functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.