Umbraco

Security Advisory, January 21, 2025 - Patches for Umbraco CMS are now available

We recommend you upgrade to the latest patch

Andy Butland
Written by Andy Butland

Summary: We have identified three, unrelated security vulnerabilities in Umbraco CMS. These vulnerabilities may allow for potential code execution and identification of backoffice user account names. Today, we have released patches for all affected versions and recommend upgrading to the latest patch. Projects hosted on Umbraco Cloud will receive the fix automatically.

Who’s affected?

  • Umbraco 10.0.0 - 10.8.7
    • Umbraco 10 is affected by 1 moderate-severity issue.
  • Umbraco 13.0.0 - 13.5.2
    • Umbraco 13 is affected by 1 moderate-severity issue.
  • Umbraco 14.0.0 - 14.3.1 and Umbraco 15.0.0 - 15.1.1.
    • Umbraco 14 and 15 are affected by 3 moderate-severity issues.

Umbraco 8 and below are not affected.

How to fix the vulnerability

Patches are available for the latest minor on each supported major version. Sites will need to update to the latest minor version before the patch can be applied. As we are looking at a patch upgrade, and the fix is straightforward, we expect the patch upgrade to only require minimal effort per project.

Instructions on patch availability and how to upgrade can be found in the release notes:

Automatic fix on Umbraco Cloud

All Umbraco Cloud sites running the latest minor version of a supported version are patched via the automated patch feature. The security patches will be rolled out to Umbraco Cloud today to ensure all sites have been fixed.

If a project is not running the latest minor version (10.8.x, 13.5.x, 14.3.x, 15.1.x), the patch can be applied using the minor upgrade feature.

Screenshot form the Umbraco Cloud Portal showing the option to turn on Automatic Minor Upgrades

Note that Umbraco Cloud also supports automated minor upgrades. This can be enabled on a per-project level and ensures you're always ready to receive the latest patch.

What we know about the vulnerability

For more details please refer to the security advisories:

There are no indications that the vulnerabilities were discovered or exploited prior to the report. Further details will be published on the Security Advisories at a later date.

Credit

We'd like to thank Pratik Patil from NetSPI, Ivan Valadares, and kushkira for reporting issues and responsible disclosure of details regarding the vulnerability.

We'd also like to give our appreciation to Anna Bastron and Steven Harland from the Security & Privacy Community Team for their assistance in reproducing issues and reviewing proposed solutions.

Any questions?

If you have any questions or comments about this advisory, make sure to get in touch with us directly on the Security Advisories. Alternatively, you can reach out to the dedicated security email address listed at https://umbraco.com/security. Here you can also find information on how we handle security-related issues.