CVE-2024-29035

U

mbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.

Configurations

Configuration 1 (hide)

cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*

History

12 Feb 2025, 15:26

Type Values Removed Values Added
First Time Umbraco
Umbraco umbraco Cms
CPE cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
References () https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0 - () https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0 - Patch
References () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3 - () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3 - Vendor Advisory
CWE NVD-CWE-noinfo

21 Nov 2024, 09:07

Type Values Removed Values Added
References () https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0 - () https://github.com/umbraco/Umbraco-CMS/commit/6b8067815c02ae43161966a8075a3585e1bc4de0 -
References () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3 - () https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-74p6-39f2-23v3 -

Information

Published : 2024-04-17 15:15

Updated : 2025-02-12 15:26


NVD link : CVE-2024-29035

Mitre link : CVE-2024-29035

CVE.ORG link : CVE-2024-29035


JSON object : View

Products Affected
CWE
CWE-918

Server-Side Request Forgery (SSRF)

NVD-CWE-noinfo