Strapi Protected Populate Plugin leaking fields if the request fields where empty or only fields selected where not populatable
CVE-2023-48218

5.3MEDIUM

Key Information:

Vendor
CVE Published:
20 November 2023

What is CVE-2023-48218?

The Strapi Protected Populate Plugin protects get endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass the field level security. Users who tried to populate something that they didn't have access to could populate those fields anyway. This issue has been patched in version 1.3.4. There are no known workarounds.

Affected Version(s)

strapi-plugin-protected-populate < 1.3.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.