Umbraco.Cms is vulnerable to Observable Response Discrepancy
51
Medium Risk
Affected versions of the package are vulnerable to observable response discrepancy. By analyzing the timing of post-login API responses, an attacker can infer the existence of user accounts.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Observable Response Discrepancy in versions 11.0.0 - 13.8.0 and 9.0.0 - 10.8.9.
Upgrade the Umbraco.Cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant