Umbraco allows possible Admin-level access to backoffice without Auth under rare conditions
Description
Published by the National Vulnerability Database
Jul 13, 2023
Published to the GitHub Advisory Database
Jul 13, 2023
Reviewed
Jul 13, 2023
Last updated
Nov 4, 2023
Under rare conditions, a restart of Umbraco can allow unauthorized users to gain admin-level permissions.
Impact
An unauthorized user gaining admin-level access and permissions to the backoffice.
Patches
10.6.1, 11.4.2, 12.0.1
Workarounds
*/install/*
and*/umbraco/*
will limit the exposure to allowed IP addresses.References