MEDIUM 5.3
GHSA-pgvc-6h2p-q4f6
Umbraco CMS disclosure of configured password requirements
상세
### Impact Via a request to an anonymously authenticated endpoint it's possible to retrieve information about the configured password requirements. The information available is limited but would perhaps give some additional detail useful for someone attempting to brute force derive a user's password.
The vulnerability can be found in the supported Umbraco versions 10 and 13. It was not exposed in Umbraco 7 or 8, nor in 14 or higher versions.
### Patches Patched in 10.8.11 and 13.9.2
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
NuGet / Umbraco.Cms
최초 영향 버전:
10.0.0 수정 버전: 10.8.11 수정
dotnet add package Umbraco.Cms --version 10.8.11 NuGet / Umbraco.Cms
최초 영향 버전:
13.0.0 수정 버전: 13.9.2 수정
dotnet add package Umbraco.Cms --version 13.9.2 참고
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-pgvc-6h2p-q4f6 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-49147 [ADVISORY]
- https://github.com/umbraco/Umbraco-CMS/commit/b4144564c836ec6929111ce2a12eb1f67b42d61e [WEB]
- https://github.com/umbraco/Umbraco-CMS/commit/d8f68d2c40f8e158bd81d469f25ef3a4e1d86c4c [WEB]
- https://github.com/umbraco/Umbraco-CMS [PACKAGE]