PT-2023-25867 · Strapi · Strapi
Boegie19
·
Published
2023-09-13
·
Updated
2024-09-25
·
CVE-2023-37263
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi versions prior to 4.12.1
Description
The issue concerns field level permissions not being respected in the relationship title. If an actor has a relationship title and the relationship shows a field they don't have permission to see, the field will still be visible. This could lead to data leaks of sensitive fields that the actor should not be allowed to see. The problem arises due to the lack of Role-Based Access Control (RBAC) checks on the relationship endpoint.
Recommendations
For Strapi versions prior to 4.12.1, update to version 4.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the relationship title feature until the update is applied. Additionally, review and adjust the permissions for all roles to ensure that they do not have access to sensitive fields they should not be able to see.
Exploit
Fix
Information Disclosure
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Strapi