CVE-2024-28868: Umbraco possible user enumeration vulnerability
Impact A user enumeration attack is possible.
Affected versions Umbraco 10 with access to the native login screen
Patches This is fixed in 10.8.5
Workarounds Disabling the native login screen, by exclusively use external logins.
Other sources
Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28868?
CVE-2024-28868 is a user enumeration vulnerability that could allow attackers to identify valid usernames.
How do I fix CVE-2024-28868?
The vulnerability can be fixed by upgrading Umbraco CMS to version 10.8.5 or later.
What versions are affected by CVE-2024-28868?
CVE-2024-28868 affects Umbraco CMS version 10.0.0 to 10.8.4.
Is there a workaround for CVE-2024-28868?
A temporary workaround for CVE-2024-28868 is to disable the native login screen and use exclusively external logins.
Who is impacted by CVE-2024-28868?
Users with access to the native login screen of the affected Umbraco versions are impacted by CVE-2024-28868.