GHSA-h8wc-r4jh-mg7m

    Dashboard / Vulnerabilities / GHSA-h8wc-r4jh-mg7m

    GHSA-h8wc-r4jh-mg7m

    Published: 13 Jul 2023Last Modified: 16 Feb 2024

    Summary: Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions

    Details: Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions. ### Impact An unauthorized user gaining admin-level access and permissions to the backoffice. ### Patches 10.6.1, 11.4.2, 12.0.1 ### Workarounds * Enabling the [Unattended Install](https://docs.umbraco.com/umbraco-cms/reference/configuration/unattendedsettings) feature will mean the vulnerability is not exploitable. * Enabling IP restrictions to `*/install/*` and `*/umbraco/*` will limit the exposure to allowed IP addresses.

    Affected packages

    Package

    Name: Umbraco.Cms.Infrastructure

    Purl: pkg:nuget/Umbraco.Cms.Infrastructure

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 9.0.0
    Fixed -10.6.1

    Affected versions

    10.0.0
    10.0.0-rc5
    10.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-h8wc-r4jh-mg7m | CVE-DB