Server-Side Request Forgery in Strapi by Strapi Development Community
CVE-2024-37818

8.6HIGH

Key Information:

Vendor

Strapi

Status
Vendor
CVE Published:
20 June 2024

What is CVE-2024-37818?

A vulnerability in Strapi v4.24.4 enables Server-Side Request Forgery (SSRF) through the component /strapi.io/_next/image. Attackers can exploit this vulnerability to probe for open ports or potentially access sensitive data via specially crafted GET requests. The Strapi Development Community has addressed these concerns, asserting that the alleged flaw is misinterpreted and pertains specifically to the strapi.io website rather than the Strapi library itself, minimizing the actual risk it poses to applications based on Strapi.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.