{"id":"GHSA-77gj-crhp-3gvx","summary":"Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information","details":"### Impact\nSome endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.\n\n### Explanation of the vulnerability\nManagement API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.\n\nE.g. when paging with negative numbers in some apis\n\n\n","aliases":["CVE-2024-43376"],"modified":"2024-09-17T16:35:18.164467Z","published":"2024-08-20T18:25:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-08-20T18:25:15Z","nvd_published_at":"2024-08-20T15:15:23Z","cwe_ids":["CWE-209"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-77gj-crhp-3gvx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43376"},{"type":"WEB","url":"https://github.com/umbraco/Umbraco-CMS/commit/b76070c794925932cb159ef50b851db6e966a004"},{"type":"PACKAGE","url":"https://github.com/umbraco/Umbraco-CMS"}],"affected":[{"package":{"name":"Umbraco.Cms.Api.Management","ecosystem":"NuGet","purl":"pkg:nuget/Umbraco.Cms.Api.Management"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14.0.0"},{"fixed":"14.1.2"}]}],"versions":["14.0.0","14.1.0","14.1.0-rc","14.1.0-rc2","14.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}