Insufficient Session Expiration in Umbraco CMS
CVE-2024-48926
3.1LOW
What is CVE-2024-48926?
Umbraco, an open-source .NET content management system, has identified an insufficient session expiration issue across its 13.x, 10.x, and 8.x versions. This vulnerability arises when the Backoffice displays a logout page with a session timeout notification to users prematurely—approximately 30 seconds before the server session has truly ended. This could potentially mislead users into believing they have been logged out while still being within an active session. Users are urged to update to the fixed versions 13.5.2, 10.8.7, and 8.18.15 to enhance security and ensure robust session management.