Moderate severityNVD Advisory· Published Oct 22, 2024· Updated Oct 22, 2024
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
CVE-2024-48929
Description
Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7, during an explicit sign-out, the server session is not fully terminated. Versions 13.5.2 and 10.8.7 contain a patch for the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Umbraco.CMSNuGet | >= 13.0.0, < 13.5.2 | 13.5.2 |
Umbraco.CMSNuGet | >= 10.0.0, < 10.8.7 | 10.8.7 |
Affected products
1- Range: >= 13.0.0, < 13.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-wxw9-6pv9-c3xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-48929ghsaADVISORY
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wxw9-6pv9-c3xcghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.