Generation of Error Message Containing Sensitive Information
CVE-2024-43376
Summary
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in "debug" mode. This vulnerability affects Umbraco.Cms.Api.Management, and Umbraco.Cms.Web.Common packages versions 14.0.0-rc1 through 14.1.1, and 14.2.0-rc through 14.2.0-rc3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-209 - Generation of Error Message Containing Sensitive Information
The software generates an error message that includes sensitive information about its environment, users, or associated data.
References
Advisory Timeline
- Published