github.com
https://github.com/strapi/strapi CVE-2024-29181
LOW
@strapi/plugin-content-manager leaks data via relations via the Admin Panel
Record summary
CVE-2024-29181 has a selected CVSS score of 2.3 (low).
Description
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
strapiBrowse strapi / strapiDefault status: unknown | CVE List | Before 4.19.1 | affected |
| < 4.19.1 | affected | ||
@strapi/plugin-content-managerBrowse npm / @strapi/plugin-content-manager | GitHub Advisory | Before 4.19.1 · Fixed in 4.19.1 | affected |
References
4github.com
https://github.com/strapi/strapi/commit/e1dfd4d9f1cab25cf6da3614c1975e4e508e01c6 github.comConfirmation
https://github.com/strapi/strapi/security/advisories/GHSA-6j89-frxc-q26m nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-29181