PT-2024-23858 · Strapi · Strapi
Cxdavidepaalte
·
Published
2024-06-12
·
Updated
2025-12-30
·
CVE-2024-31217
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Strapi versions prior to 4.22.0
Description
A denial-of-service issue is present in the media upload process, causing the server to crash without restarting. This affects both development and production environments. Usually, errors in the application cause it to log the error and keep running for other clients, but this behavior stops the server execution, making it unavailable until manually restarted. Any user with access to the file upload functionality can exploit this issue. The estimated number of potentially affected devices is not provided.
Recommendations
For versions prior to 4.22.0, upgrade @strapi/plugin-upload to version 4.22.0 to receive a patch. As a temporary workaround, consider restricting access to the file upload functionality to minimize the risk of exploitation.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Strapi