GHSA-h8wc-r4jh-mg7m
Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Quick fix
GHSA-h8wc-r4jh-mg7m — Umbraco.Cms.Infrastructure: upgrade to the fixed version with the command below.
dotnet add package Umbraco.Cms.Infrastructure --version 10.6.1Details
Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.
### Impact An unauthorized user gaining admin-level access and permissions to the backoffice.
### Patches 10.6.1, 11.4.2, 12.0.1
### Workarounds * Enabling the [Unattended Install](https://docs.umbraco.com/umbraco-cms/reference/configuration/unattendedsettings) feature will mean the vulnerability is not exploitable. * Enabling IP restrictions to `*/install/*` and `*/umbraco/*` will limit the exposure to allowed IP addresses.
Are you affected?
Enter the version of the package you're using.
Affected packages
9.0.0Fixed in: 10.6.1dotnet add package Umbraco.Cms.Infrastructure --version 10.6.111.0.0Fixed in: 11.4.2dotnet add package Umbraco.Cms.Infrastructure --version 11.4.212.0.0Fixed in: 12.0.1dotnet add package Umbraco.Cms.Infrastructure --version 12.0.19.0.0Fixed in: 10.6.1dotnet add package Umbraco.Cms.Web.BackOffice --version 10.6.111.0.0Fixed in: 11.4.2dotnet add package Umbraco.Cms.Web.BackOffice --version 11.4.212.0.0Fixed in: 12.0.1dotnet add package Umbraco.Cms.Web.BackOffice --version 12.0.1References
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-h8wc-r4jh-mg7m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37267[ADVISORY]
- https://github.com/umbraco/Umbraco-CMS/commit/1f26f2c6f3428833892cde5c6d8441fb041e410e[WEB]
- https://github.com/umbraco/Umbraco-CMS/commit/20a4e475c8d7b91d263e4e103ef19f3644e7b569[WEB]
- https://github.com/umbraco/Umbraco-CMS/commit/82eae48d098b9deecbdf86cf288b2b18020e1fed[WEB]
- https://github.com/umbraco/Umbraco-CMS[PACKAGE]