Vulnerability Database
Blog
FAQ
Docs
GHSA-wxw9-6pv9-c3xc
Suggest an improvement
Source
https://github.com/advisories/GHSA-wxw9-6pv9-c3xc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-wxw9-6pv9-c3xc/GHSA-wxw9-6pv9-c3xc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wxw9-6pv9-c3xc
Aliases
CVE-2024-48929
Published
2024-10-22T18:13:47Z
Modified
2024-10-22T19:30:52.338723Z
Severity
4.2 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS Calculator
Summary
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Details
Impact
During an explicit sign-out, the server session is not fully terminated.
References
https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wxw9-6pv9-c3xc
https://nvd.nist.gov/vuln/detail/CVE-2024-48929
https://github.com/umbraco/Umbraco-CMS
Affected packages
NuGet
/
Umbraco.CMS
Package
Name
Umbraco.CMS
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.CMS
Affected ranges
Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.5.2
Affected versions
13.*
13.0.0
13.0.1
13.0.2
13.0.3
13.1.0-rc
13.1.0
13.1.1
13.2.0-rc
13.2.0
13.2.1
13.2.2
13.3.0-rc
13.3.0
13.3.1
13.3.2
13.4.0-rc
13.4.0-rc2
13.4.0
13.4.1
13.5.0-rc
13.5.0
13.5.1
NuGet
/
Umbraco.CMS
Package
Name
Umbraco.CMS
View open source insights on deps.dev
Purl
pkg:nuget/Umbraco.CMS
Affected ranges
Type
ECOSYSTEM
Events
Introduced
10.0.0
Fixed
10.8.7
Affected versions
10.*
10.0.0
10.0.1
10.1.0-rc
10.1.0-rc2
10.1.0
10.1.1
10.2.0-rc
10.2.0
10.2.1
10.3.0-rc
10.3.0
10.3.1
10.3.2
10.4.0-rc
10.4.0
10.4.1
10.4.2
10.5.0-rc
10.5.0
10.5.1
10.6.0-rc
10.6.0
10.6.1
10.7.0-rc
10.7.0
10.8.0-rc
10.8.0
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6
GHSA-wxw9-6pv9-c3xc - OSV