CVE-2022-2888 is a session cookie vulnerability affecting OctoPrint, where an attacker possessing a victim's session cookie can authenticate as that user. This medium-severity vulnerability (CVSS 4.4) requires local access and low privileges, allowing for limited confidentiality and integrity impact without affecting availability. While no active exploits or public exploit code exist, and community discussion is minimal, organizations should be aware of the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.3CPE matchmatch criteria | cpe:2.3:a:octoprint:octoprint:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.