First published: Tue Aug 20 2024(Updated: )
### Impact Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. ### Explanation of the vulnerability Management API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled. E.g. when paging with negative numbers in some apis
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.Cms.Api.Management | >=14.0.0<14.1.2 | 14.1.2 |
Umbraco CMS | >=14.0.0<14.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-43376 is considered a high-severity vulnerability due to the exposure of stack trace information.
To fix CVE-2024-43376, update to Umbraco CMS version 14.1.2 or later.
The potential impacts of CVE-2024-43376 include disclosing sensitive internal stack trace information to unauthorized users.
CVE-2024-43376 affects Umbraco CMS versions between 14.0.0 and 14.1.2.
There are no known workarounds for CVE-2024-43376; updating to the patched version is recommended.