CVE-2024-48926
Umbraco CMS logout page displayed before session expiration
Severity Score
4.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7, and 8.x prior to 8.18.15. The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are. Versions 13.5.2, 10.8,7, and 8.18.15 contain a patch for the issue.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-10-09 CVE Reserved
- 2024-10-22 CVE Published
- 2024-10-22 CVE Updated
- 2024-10-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-613: Insufficient Session Expiration
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-fp6q-gccw-7qqm | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Umbraco Search vendor "Umbraco" | Umbraco-CMS Search vendor "Umbraco" for product "Umbraco-CMS" | >= 13.0.0 < 13.5.2 Search vendor "Umbraco" for product "Umbraco-CMS" and version " >= 13.0.0 < 13.5.2" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco-CMS Search vendor "Umbraco" for product "Umbraco-CMS" | >= 10.0.0 < 10.8.7 Search vendor "Umbraco" for product "Umbraco-CMS" and version " >= 10.0.0 < 10.8.7" | en |
Affected
| ||||||
Umbraco Search vendor "Umbraco" | Umbraco-CMS Search vendor "Umbraco" for product "Umbraco-CMS" | >= 8.0.0 < 8.18.15 Search vendor "Umbraco" for product "Umbraco-CMS" and version " >= 8.0.0 < 8.18.15" | en |
Affected
|