CVE-2024-29181

LOW

Strapi <4.19.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.

Scores

CVSS v3 2.3
EPSS 0.0043
EPSS Percentile 62.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
strapi/plugin-content-manager 0 - 4.19.1npm
strapi/strapi < 4.19.1
Published Jun 12, 2024
Tracked Since Feb 18, 2026