Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0yODdmLTQ2ajctajR3aM4AA7R8

Umbraco Workflow's Backoffice users can execute arbitrary SQL

Impact

Backoffice users can execute arbitrary SQL.

Explanation of the vulnerability

A Backoffice user can modify requests to a particular API endpoint to include SQL which will be executed by the server.

Affected versions

All versions

Patches

Workflow 10.3.9, 12.2.6, 13.0.6, Plumber 10.1.2

References

Upgrading Umbraco Workflow

Permalink: https://github.com/advisories/GHSA-287f-46j7-j4wh
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yODdmLTQ2ajctajR3aM4AA7R8
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 10 days ago
Updated: 10 days ago


CVSS Score: 5.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

Identifiers: GHSA-287f-46j7-j4wh, CVE-2024-32872
References: Repository: https://github.com/umbraco/Umbraco.Workflow.Issues
Blast Radius: 1.0

Affected Packages

nuget:Plumber.Workflow
Dependent packages: 0
Dependent repositories: 0
Downloads: 120,774 total
Affected Version Ranges: < 10.1.2
Fixed in: 10.1.2
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.7, 1.3.8, 1.3.9, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 1.6.6, 1.6.7, 1.6.8, 2.0.0, 2.0.1, 2.0.2, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.1.10, 2.1.11, 2.1.12, 2.1.13, 10.0.0, 10.0.1, 10.1.0, 10.1.1
All unaffected versions: 10.1.2
nuget:Umbraco.Workflow
Dependent packages: 0
Dependent repositories: 0
Downloads: 59,991 total
Affected Version Ranges: >= 13.0.0-rc1, < 13.0.6, >= 11.0.0-rc1, < 12.2.6, < 10.3.9
Fixed in: 13.0.6, 12.2.6, 10.3.9
All affected versions: 10.0.0, 10.1.0, 10.1.1, 10.1.2, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.3.7, 10.3.8, 11.0.0, 11.0.0-rc1, 11.0.0-rc2, 11.0.0-rc3, 11.0.1, 11.1.0, 11.1.1, 11.1.2, 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.3.0, 11.3.1, 11.3.2, 12.0.0, 12.0.1, 12.1.0, 12.1.1, 12.1.2, 12.2.0, 12.2.1, 12.2.2, 12.2.3, 12.2.4, 12.2.5, 13.0.0, 13.0.0-rc1, 13.0.0-rc2, 13.0.1, 13.0.2, 13.0.3, 13.0.5
All unaffected versions: 10.3.9, 12.2.6, 13.0.6