GHSA-h8wc-r4jh-mg7m

Suggest an improvement
Source
https://github.com/advisories/GHSA-h8wc-r4jh-mg7m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-h8wc-r4jh-mg7m/GHSA-h8wc-r4jh-mg7m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h8wc-r4jh-mg7m
Aliases
Published
2023-07-13T17:02:07Z
Modified
2024-02-16T07:58:25.940145Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Details

Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.

Impact

An unauthorized user gaining admin-level access and permissions to the backoffice.

Patches

10.6.1, 11.4.2, 12.0.1

Workarounds

  • Enabling the Unattended Install feature will mean the vulnerability is not exploitable.
  • Enabling IP restrictions to */install/* and */umbraco/* will limit the exposure to allowed IP addresses.
Database specific
{
    "nvd_published_at": "2023-07-13T14:15:09Z",
    "cwe_ids": [
        "CWE-284"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-13T17:02:07Z"
}
References

Affected packages

NuGet / Umbraco.Cms.Infrastructure

Package

Name
Umbraco.Cms.Infrastructure
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Infrastructure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
10.6.1

Affected versions

9.*

9.0.0
9.0.1
9.1.0-rc
9.1.0
9.1.1
9.1.2
9.2.0-rc
9.2.0
9.3.0-rc
9.3.0
9.3.1
9.4.0-rc
9.4.0
9.4.1
9.4.2
9.4.3
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.0
9.5.1
9.5.2
9.5.3
9.5.4

10.*

10.0.0-rc5
10.0.0
10.0.1
10.1.0-rc
10.1.0-rc2
10.1.0
10.1.1
10.2.0-rc
10.2.0
10.2.1
10.3.0-rc
10.3.0
10.3.1
10.3.2
10.4.0-rc
10.4.0
10.4.1
10.4.2
10.5.0-rc
10.5.0
10.5.1
10.6.0-rc
10.6.0

NuGet / Umbraco.Cms.Infrastructure

Package

Name
Umbraco.Cms.Infrastructure
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Infrastructure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11.0.0
Fixed
11.4.2

Affected versions

11.*

11.0.0
11.1.0-rc
11.1.0
11.2.0-rc
11.2.0
11.2.1
11.2.2
11.3.0-rc
11.3.0
11.3.1
11.4.0-rc
11.4.0
11.4.1

NuGet / Umbraco.Cms.Infrastructure

Package

Name
Umbraco.Cms.Infrastructure
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Infrastructure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12.0.0
Fixed
12.0.1

Affected versions

12.*

12.0.0

NuGet / Umbraco.Cms.Web.BackOffice

Package

Name
Umbraco.Cms.Web.BackOffice
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Web.BackOffice

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
10.6.1

Affected versions

9.*

9.0.0
9.0.1
9.1.0-rc
9.1.0
9.1.1
9.1.2
9.2.0-rc
9.2.0
9.3.0-rc
9.3.0
9.3.1
9.4.0-rc
9.4.0
9.4.1
9.4.2
9.4.3
9.5.0-rc
9.5.0-rc2
9.5.0-rc3
9.5.0
9.5.1
9.5.2
9.5.3
9.5.4

10.*

10.0.0-rc1
10.0.0-rc2
10.0.0-rc3
10.0.0-rc4
10.0.0-rc5
10.0.0
10.0.1
10.1.0-rc
10.1.0-rc2
10.1.0
10.1.1
10.2.0-rc
10.2.0
10.2.1
10.3.0-rc
10.3.0
10.3.1
10.3.2
10.4.0-rc
10.4.0
10.4.1
10.4.2
10.5.0-rc
10.5.0
10.5.1
10.6.0-rc
10.6.0

NuGet / Umbraco.Cms.Web.BackOffice

Package

Name
Umbraco.Cms.Web.BackOffice
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Web.BackOffice

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11.0.0
Fixed
11.4.2

Affected versions

11.*

11.0.0
11.1.0-rc
11.1.0
11.2.0-rc
11.2.0
11.2.1
11.2.2
11.3.0-rc
11.3.0
11.3.1
11.4.0-rc
11.4.0
11.4.1

NuGet / Umbraco.Cms.Web.BackOffice

Package

Name
Umbraco.Cms.Web.BackOffice
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.Cms.Web.BackOffice

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12.0.0
Fixed
12.0.1

Affected versions

12.*

12.0.0