Copied to clipboard

Flag this post as spam?

This post will be reported to the moderators as potential spam to be looked at


  • Giovanni Sidoel 94 posts 233 karma points
    Feb 26, 2014 @ 11:48
    Giovanni Sidoel
    0

    Security issue v4.7

    Hey guys,

    Somebody pointed out a security issue on one of our websites running umbraco v 4.7.0 (Assembly version: 1.0.4868.25116)

    Link to the exploit http://www.exploit-db.com/exploits/19671/

    Are you aware of this issue. Has it been patched?

  • Giovanni Sidoel 94 posts 233 karma points
    Feb 27, 2014 @ 14:40
    Giovanni Sidoel
    0

    Is this the same vulnerability as listed here or is this a different one? 

  • Giovanni Sidoel 94 posts 233 karma points
    Mar 03, 2014 @ 14:34
    Giovanni Sidoel
    0

    I've sorted this out with Sebastiaan. If you have any concerns please contact [email protected].

  • Sebastiaan Janssen 5061 posts 15544 karma points MVP admin hq
    May 21, 2014 @ 13:11
    Sebastiaan Janssen
    100

    We have now issued a patch release for this issue as I failed to see the full impact back then, sorry for the delay! http://umbraco.com/follow-us/blog-archive/2014/5/20/major-vulnerability-in-umbraco-450-through-470-fixed.aspx

  • Jan Skovgaard 11280 posts 23678 karma points MVP 11x admin c-trib
    May 21, 2014 @ 13:18
    Jan Skovgaard
    0

    Hey Sebastiaan...is it correct that 4.7.1 and 4.7.2 are NOT affected by this?

    Cheers, Jan

  • Sebastiaan Janssen 5061 posts 15544 karma points MVP admin hq
    May 21, 2014 @ 13:46
    Sebastiaan Janssen
    0

    @Jan Quote:

    A few years ago we fixed a security issue in Umbraco 4.7.1 which we weren't aware could have more impact then we thought at the time.

    So yes, correct... we fixed it in 4.7.1, but not for earlier versions. Else there would've been patches for other versions as well.

  • Jan Skovgaard 11280 posts 23678 karma points MVP 11x admin c-trib
    May 21, 2014 @ 13:47
    Jan Skovgaard
    0

    Thanks, thought so but just had to be 100% sure - And seems I missed the highligthed part when I read the blogpost :)

    XOXO Jan

  • This forum is in read-only mode while we transition to the new forum.

    You can continue this topic on the new forum by tapping the "Continue discussion" link below.

Please Sign in or register to post replies