First published: Tue Oct 22 2024(Updated: )
### Impact During an explicit sign-out, the server session is not fully terminated.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.CMS | >=10.0.0<10.8.7 | 10.8.7 |
nuget/Umbraco.CMS | >=13.0.0<13.5.2 | 13.5.2 |
Umbraco CMS | >=10.0<10.8.7 | |
Umbraco CMS | >=13.0<13.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48929 has a medium severity due to improper session termination during sign-out.
To fix CVE-2024-48929, upgrade Umbraco CMS to version 10.8.7 or 13.5.2.
CVE-2024-48929 affects Umbraco CMS versions 10.0.0 to 10.8.6 and 13.0.0 to 13.5.1.
CVE-2024-48929 is a session management vulnerability related to improper sign-out processes.
Yes, CVE-2024-48929 can be exploited to potentially hijack user sessions due to incomplete session termination.