PT-2023-25867 · Strapi · Strapi

Boegie19

·

Published

2023-09-13

·

Updated

2024-09-25

·

CVE-2023-37263

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions prior to 4.12.1
Description The issue concerns field level permissions not being respected in the relationship title. If an actor has a relationship title and the relationship shows a field they don't have permission to see, the field will still be visible. This could lead to data leaks of sensitive fields that the actor should not be allowed to see. The problem arises due to the lack of Role-Based Access Control (RBAC) checks on the relationship endpoint.
Recommendations For Strapi versions prior to 4.12.1, update to version 4.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the relationship title feature until the update is applied. Additionally, review and adjust the permissions for all roles to ensure that they do not have access to sensitive fields they should not be able to see.

Exploit

Fix

Information Disclosure

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-37263
GHSA-M284-85MF-CGRC

Affected Products

Strapi