PT-2024-22786 · Strapi · Strapi+1
Felixdkatt
·
Published
2024-06-12
·
Updated
2024-09-26
·
CVE-2024-29181
CVSS v3.1
2.3
Low
| Vector | AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Strapi versions prior to 4.19.1
Description
The issue concerns Strapi, an open-source content management system. In affected versions, when a super admin creates a collection with an item associated to another collection, a user with the Author Role can see the list of associated items they did not create. Ideally, they should only see their own items. This results in authors having access to protected data created by admins, which could include sensitive information like passwords or emails.
Recommendations
For Strapi versions prior to 4.19.1, upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch. As a temporary workaround, consider restricting access to associated items in collections to minimize the risk of unauthorized data access.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Strapi/Plugin-Content-Manager
Strapi