HIGH 7.5 NuGet

Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions

GHSA-h8wc-r4jh-mg7m · CVE-2023-37267

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.

Impact

An unauthorized user gaining admin-level access and permissions to the backoffice.

Patches

10.6.1, 11.4.2, 12.0.1

Workarounds

  • Enabling the Unattended Install feature will mean the vulnerability is not exploitable.
  • Enabling IP restrictions to */install/* and */umbraco/* will limit the exposure to allowed IP addresses.

Ready to move

Start Securing

Free, no credit card | First findings in minutes