Junglewise Threat Intelligence

CVE-2022-30617: Strapi sensitive information disclosure in admin responses

CVE-2022-30617 · Severity: low · CVSS 3.1 · Published 2022-05-20

Technologies: @strapi/strapi (npm), strapi (npm). Vendors: npm, Strapi.

Executive brief

Strapi is an open-source headless CMS platform used to manage and deliver content to web and mobile applications. An authenticated user with low privileges can view sensitive data (such as password reset tokens and email addresses) of other admin users by examining JSON responses from content they can access. This allows attackers to compromise higher-privileged accounts, including full administrative control of the Strapi instance, enabling data theft, unauthorized modifications, and complete system lockdown.

Technical details

The vulnerability is an improper removal of sensitive information (CWE-212) in Strapi's API responses. When a low-privileged authenticated user accesses content (e.g., a blog post), the JSON response includes sensitive user metadata (password reset tokens, email addresses) from related admin accounts (those who created or updated the content). The root cause is insufficient data filtering before serialization. An authenticated attacker can exploit this through direct API calls by accessing any content with relationships to higher-privileged users. No user interaction is required beyond initial authentication. Successful exploitation enables lateral movement and privilege escalation up to super-admin level. Patches are available: strapi <3.6.9 and @strapi/strapi <4.0.0-beta.15 are affected; updates to 3.6.9 or 4.0.0-beta.15+ are required.

Affected products

  • Strapi Strapi 3.0.0 to 3.6.8
  • Strapi Strapi 4.0.0-beta.1 to 4.0.0-beta.14

Timeline

  • 2022-05-20: disclosed
  • 2022-05-20: patched: Patches available: strapi 3.6.9, @strapi/strapi 4.0.0-beta.15

References

Related threats