Loading HuntDB...

GHSA-fp6q-gccw-7qqm

GitHub Security Advisory

Umbraco CMS logout page displayed before session expiration

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

### Impact
The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are.

Affected Packages

NuGet Umbraco.CMS
Affected versions: 13.0.0 (fixed in 13.5.2)
NuGet Umbraco.CMS
Affected versions: 10.0.0 (fixed in 10.8.7)
NuGet UmbracoCMS
Affected versions: 8.0.0 (fixed in 8.18.15)

Related CVEs

Key Information

GHSA ID
GHSA-fp6q-gccw-7qqm
Published
October 22, 2024 5:55 PM
Last Modified
October 22, 2024 7:22 PM
CVSS Score
5.0 /10
Primary Ecosystem
NuGet
Primary Package
Umbraco.CMS
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 11, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.