CVE-2023-37267: Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Umbracoto a version that resolves this vulnerability.Fixed in 10.6.1 - Upgrade
Upgrade
Umbracoto a version that resolves this vulnerability.Fixed in 11.4.2 - Upgrade
Upgrade
Umbracoto a version that resolves this vulnerability.Fixed in 12.0.1
Event History
Frequently Asked Questions
What is CVE-2023-37267?
CVE-2023-37267 is a vulnerability in Umbraco CMS that can allow unauthorized users access to admin-level permissions.
How severe is CVE-2023-37267?
CVE-2023-37267 is considered a critical vulnerability with a severity score of 9.8.
How does CVE-2023-37267 affect Umbraco CMS?
Under rare conditions, a restart of Umbraco CMS can allow unauthorized users access to admin-level permissions.
Which versions of Umbraco CMS are affected by CVE-2023-37267?
Umbraco CMS versions 10.0.0 to 10.6.1, 11.0.0 to 11.4.2, and 12.0.0 to 12.0.1 are affected by CVE-2023-37267.
How can I fix CVE-2023-37267?
You can fix CVE-2023-37267 by updating your Umbraco CMS to versions 10.6.1, 11.4.2, or 12.0.1, where the vulnerability has been patched.