VulnerabilityAnalyzed
CVE-2024-29035
This vulnerability is fixed in 13.1.1.
MEDIUM 5.3EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.43% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- umbraco/umbraco cms
- Source
- security-advisories@github.com
References
- https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0Patch
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3Vendor Advisory
- https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0Patch
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.