QID 379489

Date Published: 2024-04-01

QID 379489: Kentico Deserialization of Untrusted Data Vulnerability

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

Affected Versions
Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions.

QID Detection Logic (Authenticated)
This qid checks for vulnerable version of Kentico

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to here to address this issue and obtain more information.

    CVEs related to QID 379489

    Software Advisories
    Advisory ID Software Component Link
    CVE-2019-10068 Windows URL Logo devnet.kentico.com/download/hotfixes#securityBugs-v12