CVE-2024-43376: Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Impact Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.
Explanation of the vulnerability Management API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.
E.g. when paging with negative numbers in some apis
Other sources
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43376?
CVE-2024-43376 is considered a high-severity vulnerability due to the exposure of stack trace information.
How do I fix CVE-2024-43376?
To fix CVE-2024-43376, update to Umbraco CMS version 14.1.2 or later.
What are the potential impacts of CVE-2024-43376?
The potential impacts of CVE-2024-43376 include disclosing sensitive internal stack trace information to unauthorized users.
Which versions of Umbraco CMS are affected by CVE-2024-43376?
CVE-2024-43376 affects Umbraco CMS versions between 14.0.0 and 14.1.2.
Are there any workarounds for CVE-2024-43376?
There are no known workarounds for CVE-2024-43376; updating to the patched version is recommended.