Data Exposure Vulnerability in Strapi Admin Panel by Strapi
CVE-2022-30617
What is CVE-2022-30617?
An authenticated user with access to the Strapi admin panel may mistakenly gain visibility into private information of other users, including email addresses and password reset tokens. This data leakage occurs when a user’s actions trigger a JSON response that inadvertently includes sensitive details from linked user accounts, such as those who have edited or created content. In scenarios where a low-privileged 'author' role has associated actions with a more privileged user, they may access their private information. This vulnerability allows for the potential compromise of accounts, as attackers could exploit the password reset mechanism to take over accounts of higher-privileged users, including 'super admins,' granting them extensive control over the Strapi environment.
Affected Version(s)
Strapi < 3.6.9 < 3.6.9
Strapi ! 4.0.0
Strapi < 4.0.0-beta.16 < 4.0.0-beta.16
