GHSA-wxw9-6pv9-c3xc

Suggest an improvement
Source
https://github.com/advisories/GHSA-wxw9-6pv9-c3xc
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-wxw9-6pv9-c3xc/GHSA-wxw9-6pv9-c3xc.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wxw9-6pv9-c3xc
Aliases
Published
2024-10-22T18:13:47Z
Modified
2024-10-22T19:33:04.026882Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Details

Impact

During an explicit sign-out, the server session is not fully terminated.

References

Affected packages

NuGet / Umbraco.CMS

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.5.2

Affected versions

13.*

13.0.0
13.0.1
13.0.2
13.0.3
13.1.0-rc
13.1.0
13.1.1
13.2.0-rc
13.2.0
13.2.1
13.2.2
13.3.0-rc
13.3.0
13.3.1
13.3.2
13.4.0-rc
13.4.0-rc2
13.4.0
13.4.1
13.5.0-rc
13.5.0
13.5.1

NuGet / Umbraco.CMS

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.0.0
Fixed
10.8.7

Affected versions

10.*

10.0.0
10.0.1
10.1.0-rc
10.1.0-rc2
10.1.0
10.1.1
10.2.0-rc
10.2.0
10.2.1
10.3.0-rc
10.3.0
10.3.1
10.3.2
10.4.0-rc
10.4.0
10.4.1
10.4.2
10.5.0-rc
10.5.0
10.5.1
10.6.0-rc
10.6.0
10.6.1
10.7.0-rc
10.7.0
10.8.0-rc
10.8.0
10.8.1
10.8.2
10.8.3
10.8.4
10.8.5
10.8.6