Data Exposure in Strapi Admin Panel Affects User Accounts
CVE-2022-30618

7.5HIGH

Key Information:

Vendor

Strapi

Status
Vendor
CVE Published:
19 May 2022

What is CVE-2022-30618?

An authenticated user with access to the Strapi admin panel may inadvertently expose sensitive data, such as email addresses and password reset tokens of API users. This occurs when the content types available to the authenticated user have relationships with API users. The vulnerability is especially concerning as it may allow a low-privileged user to exploit the situation, potentially gaining access to higher-privileged user accounts. If enabled, this could lead to the manipulation of user data and compromise of account security, as an attacker could read, modify, or revoke access to the admin panel and API effectively locking out legitimate users. Prompt action is recommended to address this data exposure risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Strapi < 3.6.10 < 3.6.10

Strapi < 4.1.10 < 4.1.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.