Record summary

CVE-2023-38507 has a selected CVSS score of 7.3 (high).

Description

Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack increases. Version 4.12.1 has a fix for this issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 4.12.1affected
GitHub AdvisoryBefore 4.12.1 · Fixed in 4.12.1affected

@strapi/plugin-users-permissions

Browse npm / @strapi/plugin-users-permissions
GitHub AdvisoryBefore 4.12.1 · Fixed in 4.12.1affected

References

5