NuGet package
umbraco.cms.core
pkg:nuget/umbraco.cms.core
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-29035 | — | >= 13.0.0, < 13.1.1 | 13.1.1 | Apr 17, 2024 | Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1. | ||
| CVE-2022-22690 | — | < 9.2.0 | 9.2.0 | Jan 18, 2022 | Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the application builds a password reset UR | ||
| CVE-2022-22691 | — | < 9.2.0 | 9.2.0 | Jan 18, 2022 | The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the |
- CVE-2024-29035Apr 17, 2024affected >= 13.0.0, < 13.1.1fixed 13.1.1
Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.
- CVE-2022-22690Jan 18, 2022affected < 9.2.0fixed 9.2.0
Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used whenever application code needs to build a URL pointing back to the site. For example, when a user resets their password and the application builds a password reset UR
- CVE-2022-22691Jan 18, 2022affected < 9.2.0fixed 9.2.0
The password reset component deployed within Umbraco uses the hostname supplied within the request host header when building a password reset URL. It may be possible to manipulate the URL sent to Umbraco users when so that it points to the attackers server thereby disclosing the