CVE-2024-29035

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-29035
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-29035.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-29035
Aliases
Published
2024-04-17T14:20:05.701Z
Modified
2025-11-28T04:56:20.540255Z
Severity
  • 4.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Umbraco's Blind SSRF Leads to Port Scan by using Webhooks
Details

Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29035.json"
}
References

Affected packages

Git / github.com/umbraco/umbraco-cms

Affected ranges

Type
GIT
Repo
https://github.com/umbraco/umbraco-cms
Events

Affected versions

release-10.*

release-10.8.1
release-10.8.2
release-10.8.3

release-12.*

release-12.3.4
release-12.3.5
release-12.3.6

release-13.*

release-13.0.0
release-13.0.1
release-13.0.2
release-13.0.3
release-13.1.0
release-13.1.0-rc