Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 NuGet

Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions

GHSA-h8wc-r4jh-mg7m · CVE-2023-37267

Published · Modified

Description

Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.

Impact

An unauthorized user gaining admin-level access and permissions to the backoffice.

Patches

10.6.1, 11.4.2, 12.0.1

Workarounds

  • Enabling the Unattended Install feature will mean the vulnerability is not exploitable.
  • Enabling IP restrictions to */install/* and */umbraco/* will limit the exposure to allowed IP addresses.

Ready to move

Start Securing

Free, no credit card | First findings in minutes