It seems like this could be a BIG problem depending on your configuration.
If confirmed, we need some documentation if it was indeed fixed in 9.2.0 and confirmation on which versions (including major versions) are impacted. Not to mention a suitable notification being sent out, or at minimum, a post on https://umbraco.com/blog/category/security/
Account Takeover Vulnerabilities: CVE-2022-22690 & CVE-2022-22691
Can these vulnerabilities be confirmed by Umbraco?: CVE-2022-22690 & CVE-2022-22691 https://appcheck-ng.com/umbraco-applicationurl-overwrite-persistent-password-reset-poison-cve-2022-22690-cve-2022-22691/
It seems like this could be a BIG problem depending on your configuration.
If confirmed, we need some documentation if it was indeed fixed in 9.2.0 and confirmation on which versions (including major versions) are impacted. Not to mention a suitable notification being sent out, or at minimum, a post on https://umbraco.com/blog/category/security/
Thanks Mike for your question, we have just blogged about this and opened a dedicated forum topic, please add additional questions here: https://our.umbraco.com/forum/using-umbraco-and-getting-started/108070
Thanks for that Seb, good to know.
Thankfully we have umbracoApplicationUrl set on all instances and they're nearly all on Azure App Services too.
is working on a reply...