MEDIUM4.3
GHSA-77gj-crhp-3gvx
Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Quick fix
GHSA-77gj-crhp-3gvx — Umbraco.Cms.Api.Management: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Cms.Api.Management --version 14.1.2Details
### Impact Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.
### Explanation of the vulnerability Management API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.
E.g. when paging with negative numbers in some apis
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Umbraco.Cms.Api.Management
Introduced in:
14.0.0Fixed in: 14.1.2Fix
dotnet add package Umbraco.Cms.Api.Management --version 14.1.2