Skip to content

Webhook logs viewable without Umbraco is in Debug mode

Moderate
netcamo published GHSA-74p6-39f2-23v3 Apr 17, 2024

Package

nuget Umbraco (NuGet)

Affected versions

>= 13.0.0

Patched versions

13.1.1

Description

Impact

Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical.

Affected Versions

Umbraco versions 13.0.0 - 13.1.1

Patches

13.1.1

Workarounds

Disabling webhooks functionality.

Severity

Moderate
4.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

CVE ID

CVE-2024-29035

Weaknesses

No CWEs

Credits