PT-2023-25867 · Strapi · Strapi
Boegie19
·
Publicado
2023-09-13
·
Atualizado
2024-09-25
·
CVE-2023-37263
CVSS v3.1
6.8
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi versions prior to 4.12.1
Description
The issue concerns field level permissions not being respected in the relationship title. If an actor has a relationship title and the relationship shows a field they don't have permission to see, the field will still be visible. This could lead to data leaks of sensitive fields that the actor should not be allowed to see. The problem arises due to the lack of Role-Based Access Control (RBAC) checks on the relationship endpoint.
Recommendations
For Strapi versions prior to 4.12.1, update to version 4.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the relationship title feature until the update is applied. Additionally, review and adjust the permissions for all roles to ensure that they do not have access to sensitive fields they should not be able to see.
Exploit
Correção
Information Disclosure
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Strapi