Junglewise Threat Intelligence

CVE-2022-31367: Strapi information disclosure via hidden attributes in admin API

CVE-2022-31367 · Severity: low · CVSS 3.1 · Published 2022-09-28

Technologies: @strapi/strapi (npm), strapi (npm). Vendors: npm, Strapi.

Executive brief

Strapi, a popular headless CMS platform, improperly exposes sensitive database attributes (such as password hashes) marked as "hidden" in API responses accessible to authenticated admin users. An authenticated administrator can retrieve sensitive data including user password hashes and other protected fields through API filtering manipulation, potentially enabling account compromise and unauthorized access.

Technical details

This vulnerability is a column name injection / SQL injection flaw in Strapi's admin API filtering mechanism. When an authenticated user with "read user data" permissions uses the filter feature, the application fails to properly sanitize hidden attributes (fields marked as hidden in the content type configuration), returning them in API responses despite being intended to be hidden. An attacker can manipulate filter parameters (e.g., changing "email_contains" to "password_contains") to retrieve password hashes and other sensitive columns. The attack requires prior authentication and the targeted user permission level, but no additional user interaction. The vulnerability affects Strapi versions below 3.6.10 and 4.0.0 through 4.1.9. Patches were released on 2022-05-11 in versions 3.6.10 and 4.1.10, which sanitize hidden attributes from admin API responses.

Affected products

  • Strapi strapi < 3.6.10
  • Strapi @strapi/strapi 4.0.0-next.0 to < 4.1.10

Timeline

  • 2021-12-09: disclosed: Vulnerability discovered
  • 2022-05-11: patched: Security patches released in v3.6.10 and v4.1.10
  • 2022-09-27: advisory: Public disclosure via CVE-2022-31367
  • 2022-09-28: advisory: GHSA advisory published

References

Related threats