Improper Attribute Handling in Strapi Admin API
CVE-2022-31367
8.8HIGH
What is CVE-2022-31367?
The Strapi content management system versions prior to 3.6.10 and 4.1.10 are vulnerable due to a failure in properly managing hidden attributes in admin API responses. This mismanagement could potentially expose sensitive information through the API, allowing unauthorized access or manipulation of data. It is crucial for users to update to the latest versions to mitigate this vulnerability.
