CVE-2024-34071: Open Redirect Bypass Protection
Impact Umbraco have an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice, before the vulnerability is exposed.
Affected Version
\>= 8.18.5, >= 10.5.0, >= 12.0.0, >= 13.0.0
Patches 8.18.14, 10.8.6, 12.3.10, 13.3.1
Other sources
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirects. The endpoint is protected so it requires the user to be signed into backoffice before the vulnerable is exposed. This vulnerability has been patched in version(s) 8.18.14, 10.8.6, 12.3.10 and 13.3.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34071?
CVE-2024-34071 is classified as a moderate severity vulnerability due to its potential for exploitation through open redirects.
How do I fix CVE-2024-34071?
To fix CVE-2024-34071, upgrade to the patched versions: 8.18.14, 10.8.6, 12.3.10, or 13.3.1.
What versions of Umbraco are affected by CVE-2024-34071?
CVE-2024-34071 affects Umbraco versions 8.18.5 and higher, including 10.5.0, 12.0.0, and 13.0.0.
Is user authentication required to exploit CVE-2024-34071?
Yes, exploitation of CVE-2024-34071 requires the user to be signed into the Umbraco backoffice.
What type of vulnerability is CVE-2024-34071?
CVE-2024-34071 is an open redirect vulnerability that could lead to phishing attacks if exploited.