Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes
Moderate severity
GitHub Reviewed
Published
Jan 21, 2025
in
umbraco/Umbraco-CMS
•
Updated Jan 21, 2025
Package
Affected versions
>= 14.0.0, < 14.3.2
>= 15.0.0, < 15.1.2
Patched versions
14.3.2
15.1.2
Description
Published by the National Vulnerability Database
Jan 21, 2025
Published to the GitHub Advisory Database
Jan 21, 2025
Reviewed
Jan 21, 2025
Last updated
Jan 21, 2025
Impact
Based on an analysis of response codes and timing of Umbraco 14+ management API responses, it's possible to determine whether an account exists.
Patches
Will be patched in 14.3.2 and 15.1.2.
Workarounds
None available.
References