PT-2024-22786 · Strapi · Strapi+1

Felixdkatt

·

Published

2024-06-12

·

Updated

2024-09-26

·

CVE-2024-29181

CVSS v3.1

2.3

Low

VectorAV:A/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Strapi versions prior to 4.19.1
Description The issue concerns Strapi, an open-source content management system. In affected versions, when a super admin creates a collection with an item associated to another collection, a user with the Author Role can see the list of associated items they did not create. Ideally, they should only see their own items. This results in authors having access to protected data created by admins, which could include sensitive information like passwords or emails.
Recommendations For Strapi versions prior to 4.19.1, upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch. As a temporary workaround, consider restricting access to associated items in collections to minimize the risk of unauthorized data access.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-29181
GHSA-6J89-FRXC-Q26M

Affected Products

@Strapi/Plugin-Content-Manager
Strapi