PT-2024-30539 · Umbraco · Umbraco Cms

Bergmania

·

Published

2024-08-20

·

Updated

2024-08-26

·

CVE-2024-43377

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Umbraco CMS versions prior to 14.1.2
Description The issue allows an authenticated user to access a few unintended endpoints. This is because a few endpoints in the Umbraco Management API were not properly protected, requiring only authentication. As a result, it was possible to retrieve information from these endpoints using a member token.
Recommendations For versions prior to 14.1.2, update to version 14.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the unintended endpoints in the Umbraco Management API until the update is applied.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-43377
GHSA-HRWW-X3FQ-XCVH

Affected Products

Umbraco Cms