Headline
GHSA-fp6q-gccw-7qqm: Umbraco CMS logout page displayed before session expiration
Impact
The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are.
- GitHub Advisory Database
- GitHub Reviewed
- CVE-2024-48926
Umbraco CMS logout page displayed before session expiration
Moderate severity GitHub Reviewed Published Oct 22, 2024 in umbraco/Umbraco-CMS • Updated Oct 22, 2024
Package
nuget Umbraco.CMS (NuGet)
Affected versions
>= 13.0.0, < 13.5.2
>= 10.0.0, < 10.8.7
Patched versions
13.5.2
10.8.7
Impact
The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are.
References
- GHSA-fp6q-gccw-7qqm
Published to the GitHub Advisory Database
Oct 22, 2024
Last updated
Oct 22, 2024