CVE-2023-37267

Source
https://cve.org/CVERecord?id=CVE-2023-37267
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37267.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-37267
Aliases
Published
2023-07-13T13:43:59.383Z
Modified
2025-12-20T02:51:48.567475Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Details

Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/37xxx/CVE-2023-37267.json"
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Database specific
{
    "versions": [
        {
            "introduced": "9.0.0"
        },
        {
            "fixed": "10.6.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Database specific
{
    "versions": [
        {
            "introduced": "11.0.0"
        },
        {
            "fixed": "11.4.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "= 12.0.0"
        }
    ]
}

Affected versions

4.*
4.7.2
4.8.0-beta
7.*
7.3.0-beta
7.6-alpha071
7.6-beta5
Release-4.*
Release-4.10.0
Release-4.11.0
Release-4.11.1
Release-4.11.2
Release-4.11.2.1
Release-4.11.2.2
Release-4.11.3
Release-4.11.4
Release-4.11.5
Release-4.5.2
Release-4.6.0
Release-4.8.0
Release-4.8.1
Release-4.9.0
Release-4.9.1
Release-6.*
Release-6.0.0
Release-6.0.0-RC
Release-6.0.0-beta
Release-6.0.2
Other
Sprint-Juno-A
alpha070
release-netcore-alpha002
release-netcore-alpha004
temp8-cg18
dev-7.*
dev-7.6-RC1
dev-7.6-RC2
dev-7.6-RC3
dev-7.6-alpha-073
dev-7.6-alpha054
dev-7.6-alpha055
dev-7.6-alpha056
dev-7.6-alpha060
dev-7.6-alpha061
dev-7.6-alpha063
dev-7.6-alpha064
dev-7.6-alpha072
dev-7.6-alpha073
dev-7.6-alpha074
dev-7.6-alpha075
dev-7.6-beta02
dev-7.6-beta03
dev-7.6-beta04
dev-7.6-beta06
dev-v7.*
dev-v7.6-alpha065
dev-v7.6-alpha066
dev-v7.6-alpha068
dev-v7.7-beta002
release-10.*
release-10.0.0
release-10.0.0-rc1
release-10.0.0-rc2
release-10.0.0-rc3
release-10.0.0-rc4
release-10.0.0-rc5
release-10.0.1
release-10.1.0
release-10.1.0-rc
release-10.1.0-rc2
release-10.2.0
release-10.2.0-rc
release-10.2.1
release-10.3.0
release-10.3.0-rc
release-10.3.1
release-10.3.2
release-10.4.0-rc1
release-10.4.1
release-10.5.0
release-10.5.0-rc
release-10.6.0
release-10.6.0-rc
release-11.*
release-11.0.0
release-11.0.0-rc1
release-11.0.0-rc2
release-11.0.0-rc3
release-11.0.0-rc4
release-11.0.0-rc5
release-11.0.0-rc6
release-11.1.0-rc1
release-11.2.0
release-11.2.0-rc
release-11.2.1
release-11.3.0
release-11.3.0-rc
release-11.4.0
release-11.4.0-rc
release-11.4.1
release-12.*
release-12.0.0
release-12.0.0-rc1
release-12.0.0-rc2
release-12.0.0-rc3
release-12.0.0-rc4
release-12.0.0-rc5
release-4.*
release-4.11.10
release-4.11.6
release-4.11.7
release-4.11.9
release-6.*
release-6.0.3
release-6.0.4
release-6.0.6
release-6.0.7
release-6.1.0
release-6.1.0-beta
release-6.1.0-beta2
release-6.1.1
release-6.1.2
release-6.1.3
release-6.1.4
release-6.1.5
release-6.1.6
release-6.2.0
release-6.2.0-beta
release-6.2.1
release-6.2.2
release-6.2.3
release-7.*
release-7.0.0
release-7.0.0-RC
release-7.0.0-alpha
release-7.0.0-beta
release-7.0.1
release-7.0.2
release-7.0.3
release-7.0.4
release-7.1.0
release-7.1.0-RC
release-7.1.0-beta
release-7.1.1
release-7.1.2
release-7.1.3
release-7.1.4
release-7.1.5
release-7.1.6
release-7.1.7
release-7.1.8
release-7.10.0
release-7.10.1
release-7.10.2
release-7.10.3
release-7.10.4
release-7.11.0
release-7.12.0
release-7.12.1
release-7.13.0
release-7.13.1
release-7.13.2
release-7.14.0
release-7.15.0
release-7.15.1
release-7.15.2
release-7.15.3
release-7.15.4
release-7.2.0
release-7.2.0-RC
release-7.2.0-alpha
release-7.2.0-beta
release-7.2.0-beta2
release-7.2.1
release-7.2.2
release-7.2.3
release-7.2.4
release-7.2.5
release-7.2.5-RC
release-7.2.6
release-7.2.7
release-7.2.8
release-7.3.0
release-7.3.0-RC
release-7.3.0-beta
release-7.3.0-beta2
release-7.3.0-beta3
release-7.3.1
release-7.3.2
release-7.3.3
release-7.3.4
release-7.3.5
release-7.3.6
release-7.3.7
release-7.3.8
release-7.4.0
release-7.4.0-RC1
release-7.4.0-beta2
release-7.4.1
release-7.4.2
release-7.4.3
release-7.5.0
release-7.5.0-beta
release-7.5.0-beta2
release-7.5.1
release-7.5.10
release-7.5.11
release-7.5.12
release-7.5.13
release-7.5.14
release-7.5.2
release-7.5.3
release-7.5.4
release-7.5.5
release-7.5.6
release-7.5.7
release-7.5.8
release-7.5.9
release-7.6.0
release-7.6.0-RC
release-7.6.0-beta
release-7.6.1
release-7.6.2
release-7.6.3
release-7.6.4
release-7.6.5
release-7.6.6
release-7.6.7
release-7.6.8
release-7.7.0
release-7.7.0-beta
release-7.7.1
release-7.7.10
release-7.7.11
release-7.7.12
release-7.7.13
release-7.7.2
release-7.7.3
release-7.7.4
release-7.7.5
release-7.7.6
release-7.7.7
release-7.7.8
release-7.7.9
release-7.8.0
release-7.8.0-beta
release-7.8.0-beta003
release-7.8.0-beta004
release-7.8.0-beta005
release-7.8.0-beta007
release-7.8.1
release-7.8.2
release-7.8.3
release-7.9.0
release-7.9.1
release-7.9.2
release-7.9.3
release-7.9.4
release-7.9.5
release-7.9.6
release-8.*
release-8.0.0
release-8.0.01
release-8.0.1
release-8.1.0
release-8.1.1
release-8.1.2
release-8.1.3
release-8.1.4
release-8.1.5
release-8.10.0
release-8.10.0-rc
release-8.10.1
release-8.10.2
release-8.10.3
release-8.11.0
release-8.11.0-rc
release-8.11.1
release-8.11.2
release-8.11.3
release-8.12.0
release-8.12.0-rc
release-8.12.1
release-8.12.2
release-8.12.3
release-8.13.0
release-8.13.0-rc
release-8.13.1
release-8.14.0
release-8.14.0-rc
release-8.14.1
release-8.14.2
release-8.14.3
release-8.14.4
release-8.15.0
release-8.15.0-rc
release-8.15.1
release-8.15.2
release-8.15.3
release-8.16.0
release-8.16.0-rc
release-8.17.0
release-8.17.0-rc
release-8.17.0-rc2
release-8.17.1
release-8.17.2
release-8.18.0-rc
release-8.2.0
release-8.2.0-rc
release-8.2.1
release-8.2.2
release-8.3.0
release-8.4.0
release-8.4.0-rc
release-8.4.1
release-8.5.0
release-8.5.1
release-8.5.2
release-8.5.3
release-8.5.4
release-8.5.5
release-8.6.0
release-8.6.0-rc
release-8.6.1
release-8.6.2
release-8.6.3
release-8.6.4
release-8.6.5
release-8.6.6
release-8.6.7
release-8.6.8
release-8.7.0
release-8.7.0-rc
release-8.7.1
release-8.7.2
release-8.7.3
release-8.8
release-8.8.0
release-8.8.0-rc
release-8.8.1
release-8.8.2
release-8.8.3
release-8.8.4
release-8.9.0
release-8.9.0-rc
release-8.9.1
release-8.9.2
release-8.9.3
release-9.*
release-9.0.0
release-9.0.0-beta001
release-9.0.0-beta002
release-9.0.0-beta003
release-9.0.0-beta004
release-9.0.0-rc001
release-9.0.0-rc002
release-9.0.0-rc003
release-9.0.0-rc004
release-9.0.1
release-9.1.0
release-9.1.0-rc
release-9.1.1
release-9.1.2
release-9.2.0
release-9.2.0-rc
release-9.3.0
release-9.3.0-rc
release-9.3.1
release-9.4.0
release-9.4.0-rc
release-9.4.1
release-9.4.2
release-9.5.0
release-9.5.0-rc
release-9.5.0-rc2
release-9.5.0-rc3
release-9.5.1
release-netcore-0.*
release-netcore-0.5.0-alpha001
release/7.*
release/7.15.2
release/8.*
release/8.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-37267.json"