{"id":"GHSA-2vjq-hg5w-5gm7","summary":"OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled","details":"### Impact\n\nOctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication **if the `autologinLocal` option is enabled** within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, by spoofing their IP via the `X-Forwarded-For` header.\n\nIf autologin is not enabled, this vulnerability does not have any impact.\n\n### Patches\n\nThe vulnerability has been patched in version 1.10.1.\n\n### Workaround\n\nUntil the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.\n\n### PoC\n\n1. Enable the `autologinAs` configuration within the `accessControl` section in the [OctoPrint yaml configuration file](https://docs.octoprint.org/en/master/configuration/config_yaml.html#access-control)\n2. Set your browser to add the `X-Forwarded-For: 127.0.0.1` header to HTTP requests. For example, this can be done using proxy software like Burp Suite. Alternatively, there are browser extensions such as https://github.com/MisterPhilip/x-forwarded-for, but I haven't tried them.\n3. Navigate to OctoPrint and note that it logs you in automatically.\n\n### Credits\n\nThis vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi.","aliases":["CVE-2024-32977","PYSEC-2024-237"],"modified":"2026-06-10T17:14:18.648882483Z","published":"2024-05-14T20:13:47Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-05-14T20:13:47Z","nvd_published_at":"2024-05-14T16:17:12Z","cwe_ids":["CWE-290"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-2vjq-hg5w-5gm7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32977"},{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/commit/5afbec8d23508edc25b0f1bdef1620580136add4"},{"type":"PACKAGE","url":"https://github.com/OctoPrint/OctoPrint"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2024-237.yaml"}],"affected":[{"package":{"name":"octoprint","ecosystem":"PyPI","purl":"pkg:pypi/octoprint"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.1"}]}],"versions":["1.10.0","1.10.0rc1","1.10.0rc2","1.10.0rc3","1.10.0rc4","1.3.11","1.3.12","1.3.12rc1","1.3.12rc3","1.4.0","1.4.0rc1","1.4.0rc2","1.4.0rc3","1.4.0rc4","1.4.0rc5","1.4.0rc6","1.4.1","1.4.1rc1","1.4.1rc2","1.4.1rc3","1.4.1rc4","1.4.2","1.5.0","1.5.0rc1","1.5.0rc2","1.5.0rc3","1.5.1","1.5.2","1.5.3","1.6.0","1.6.0rc1","1.6.0rc2","1.6.0rc3","1.6.1","1.7.0","1.7.0rc1","1.7.0rc2","1.7.0rc3","1.7.1","1.7.2","1.7.3","1.8.0","1.8.0rc1","1.8.0rc2","1.8.0rc3","1.8.0rc4","1.8.0rc5","1.8.1","1.8.2","1.8.3","1.8.4","1.8.5","1.8.6","1.8.7","1.9.0","1.9.0rc1","1.9.0rc2","1.9.0rc3","1.9.0rc4","1.9.0rc5","1.9.0rc6","1.9.1","1.9.2","1.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-2vjq-hg5w-5gm7/GHSA-2vjq-hg5w-5gm7.json","last_known_affected_version_range":"\u003c= 1.10.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}