Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Moderate severity
GitHub Reviewed
Published
Aug 20, 2024
in
umbraco/Umbraco-CMS
•
Updated Sep 17, 2024
Package
Affected versions
>= 14.0.0, < 14.1.2
Patched versions
14.1.2
Description
Published by the National Vulnerability Database
Aug 20, 2024
Published to the GitHub Advisory Database
Aug 20, 2024
Reviewed
Aug 20, 2024
Last updated
Sep 17, 2024
Impact
Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.
Explanation of the vulnerability
Management API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.
E.g. when paging with negative numbers in some apis
References