Preface
OctoPrint is an open source 3D printer controller application that provides a web interface for connected printers. It displays printer status and key parameters, and supports scheduling print jobs and controlling the printer remotely.
Description
Numen Security Labs vulnerability researchers have discovered in OctoPrint version less than or equal to 1.9.2 that print job execution is configured with a specially crafted GCODE language script that would allow arbitrary code to be executed during the rendering of that script.
CVE ID
CVE-2023–41047
data:image/s3,"s3://crabby-images/297b5/297b5ca310f883de08d990a32a770d70b40dfeb1" alt=""
Affected Versions
< 1.9.3
Analysis
src/octoprint/server/api/settings.py#getSettings()
data:image/s3,"s3://crabby-images/68b8b/68b8b735460d50de2344a6f223133dc9bdf085bf" alt=""
Counterparts
data:image/s3,"s3://crabby-images/d76e2/d76e25dd9d651d44e743750183a9a8225adef940" alt=""
Passing the gcode to the loadScript
function of the s object
data:image/s3,"s3://crabby-images/514e6/514e60a6081f4e10f9540c5870463dfe7630018e" alt=""
The s object comes from
data:image/s3,"s3://crabby-images/e6812/e68123d99d9d5cbee0cc1faa7596188ab2525827" alt=""
data:image/s3,"s3://crabby-images/17cb3/17cb3caf0504a34e1e044dc034f822f171570b02" alt=""
src/octoprint/settings/__init__.py#loadScript()
Render using the template.render
function.
data:image/s3,"s3://crabby-images/e6d81/e6d818c30ca48ae4467055ff2e70638995bcdfeb" alt=""
The template
object comes from the _get_script_template
function.
data:image/s3,"s3://crabby-images/cbe4b/cbe4b7707839a68542c147b96b438d1278269c65" alt=""
The vulnerability is triggered by an insecure rendering of gcode, where no security measures are taken in OctoPrint, leading to this issue.
data:image/s3,"s3://crabby-images/60fd8/60fd81f64ef5f68cb29f3ed06c14f1db31ea4a62" alt=""
Fixes
Version 1.9.3 adds a security sandbox
data:image/s3,"s3://crabby-images/77caa/77caab20cc7c51d9522a7e8d828197d23f961f7d" alt=""
Timeline
- 2023–8–31 Report vulnerabilities to the OctoPrint team
- 2023–8–31 Received a response from the OctoPrint team confirming the existence of the vulnerability
- 2023–10–10 Fixing security vulnerabilities and releasing OctoPrint 1.9.3
- 2023–10–10 Public CVE
Internet Influence
More than 20,000 exposed OctoPrints were found through fofa, shodan.
data:image/s3,"s3://crabby-images/ce19c/ce19cea4717e42e51834d83fbdc05b9f2e395d15" alt=""
data:image/s3,"s3://crabby-images/6bf20/6bf201f68bfd43d149668078ebc90ee644ba343e" alt=""
Reference
https://github.com/OctoPrint/OctoPrint/releases/tag/1.9.3
https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-fwfg-vprh-97ph
https://github.com/OctoPrint/OctoPrint/commit/d0072cff894509c77e243d6562245ad3079e17db