CVE-2024-34071

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-34071
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34071.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-34071
Aliases
Published
2024-05-21T13:31:31Z
Modified
2025-10-22T18:45:54.017860Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Open Redirect Bypass Protection
Details

Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ]
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events
Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events

Affected versions

release-10.*

release-10.5.0
release-10.6.0
release-10.6.0-rc
release-10.6.1
release-10.7.0
release-10.7.0-rc
release-10.8.0
release-10.8.0-rc
release-10.8.1
release-10.8.2
release-10.8.3
release-10.8.4
release-10.8.5

release-11.*

release-11.4.1
release-11.4.2
release-11.5.0
release-11.5.0-rc

release-12.*

release-12.0.0
release-12.0.1
release-12.1.0
release-12.1.0-rc
release-12.1.1
release-12.1.2
release-12.2.0
release-12.2.0-rc
release-12.3.0
release-12.3.0-rc
release-12.3.1
release-12.3.2
release-12.3.3
release-12.3.4
release-12.3.5
release-12.3.6
release-12.3.7
release-12.3.8
release-12.3.9

release-13.*

release-13.0.0
release-13.0.1
release-13.0.2
release-13.0.3
release-13.1.0
release-13.1.0-rc
release-13.1.1
release-13.2.0
release-13.2.0-rc
release-13.2.1
release-13.2.2
release-13.3.0
release-13.3.0-rc

release/13.*

release/13.1.1