Skip to main content

Generation of Error Message Containing Sensitive Information

CVE-2024-43376

Severity Medium
Score 5.3/10

Summary

Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in "debug" mode. This vulnerability affects Umbraco.Cms.Api.Management, and Umbraco.Cms.Web.Common packages versions 14.0.0-rc1 through 14.1.1, and 14.2.0-rc through 14.2.0-rc3.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-209 - Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.

References

Advisory Timeline

  • Published