GHSA-fp6q-gccw-7qqm
GitHub Security Advisory
Umbraco CMS logout page displayed before session expiration
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
### Impact
The Backoffice displays the logout page with a session timeout message before the server session has fully expired, causing users to believe they have been logged out approximately 30 seconds before they actually are.
Affected Packages
NuGet
Umbraco.CMS
Affected versions:
13.0.0
(fixed in 13.5.2)
NuGet
Umbraco.CMS
Affected versions:
10.0.0
(fixed in 10.8.7)
NuGet
UmbracoCMS
Affected versions:
8.0.0
(fixed in 8.18.15)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.