QID 379489
Date Published: 2024-04-01
QID 379489: Kentico Deserialization of Untrusted Data Vulnerability
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Affected Versions
Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.
QID Detection Logic (Authenticated)
This qid checks for vulnerable version of Kentico
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to here to address this issue and obtain more information.
Vendor References
CVEs related to QID 379489
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2019-10068 | Windows |
|