First published: Tue May 06 2025(Updated: )
### Impact Based on an analysis of the timing of post login API responses, it's possible to determine whether an account exists. ### Patches Patched in 10.8.10 and 13.8.1. ### Workarounds None available.
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Umbraco.Cms | <10.8.10 | 10.8.10 |
nuget/Umbraco.Cms | >=11.0.0-rc1<13.8.1 | 13.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GHSA-4g8m-5mj5-c8xg has a moderate severity level due to the potential enumeration of user accounts.
To fix GHSA-4g8m-5mj5-c8xg, upgrade to Umbraco.Cms version 10.8.10 or 13.8.1.
GHSA-4g8m-5mj5-c8xg affects Umbraco.Cms versions prior to 10.8.10 and between 11.0.0-rc1 and 13.8.1.
There are no workarounds available for GHSA-4g8m-5mj5-c8xg.
The primary impact of GHSA-4g8m-5mj5-c8xg is the ability to determine if an account exists based on API response timing.