CVE-2024-29035

MEDIUM

Umbraco Cms < 13.1.1 - SSRF

Title source: rule
STIX 2.1

Description

Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. This vulnerability is fixed in 13.1.1.

Scores

CVSS v3 4.1
EPSS 0.0021
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
nuget/Umbraco.Cms.Core 13.0.0 - 13.1.1NuGet
nuget/Umbraco.Cms.Web.BackOffice 13.0.0 - 13.1.1NuGet
umbraco/umbraco_cms 13.0.0 - 13.1.1
Published Apr 17, 2024
Tracked Since Feb 18, 2026