First published: Tue Oct 22 2024(Updated: )
### Impact The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/UmbracoCMS | >=8.0.0<8.18.15 | 8.18.15 |
nuget/Umbraco.CMS | >=10.0.0<10.8.7 | 10.8.7 |
nuget/Umbraco.CMS | >=13.0.0<13.5.2 | 13.5.2 |
Umbraco CMS | >=8.0<8.18.15 | |
Umbraco CMS | >=10.0<10.8.7 | |
Umbraco CMS | >=13.0<13.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48926 has a moderate severity level as it can cause confusion for users regarding their session status.
To fix CVE-2024-48926, upgrade to UmbracoCMS version 8.18.15, Umbraco.CMS version 10.8.7, or Umbraco.CMS version 13.5.2.
CVE-2024-48926 affects UmbracoCMS versions from 8.0.0 to 8.18.15, Umbraco.CMS versions from 10.0.0 to 10.8.7, and Umbraco.CMS versions from 13.0.0 to 13.5.2.
The impact of CVE-2024-48926 is that users may incorrectly assume they have been logged out 30 seconds before their actual session expires.
Currently, no specific workarounds have been provided for CVE-2024-48926 other than upgrading to the recommended versions.