Executive brief
Strapi, a popular headless CMS platform, improperly exposes sensitive database attributes (such as password hashes) marked as "hidden" in API responses accessible to authenticated admin users. An authenticated administrator can retrieve sensitive data including user password hashes and other protected fields through API filtering manipulation, potentially enabling account compromise and unauthorized access.
Technical details
This vulnerability is a column name injection / SQL injection flaw in Strapi's admin API filtering mechanism. When an authenticated user with "read user data" permissions uses the filter feature, the application fails to properly sanitize hidden attributes (fields marked as hidden in the content type configuration), returning them in API responses despite being intended to be hidden. An attacker can manipulate filter parameters (e.g., changing "email_contains" to "password_contains") to retrieve password hashes and other sensitive columns. The attack requires prior authentication and the targeted user permission level, but no additional user interaction. The vulnerability affects Strapi versions below 3.6.10 and 4.0.0 through 4.1.9. Patches were released on 2022-05-11 in versions 3.6.10 and 4.1.10, which sanitize hidden attributes from admin API responses.
Affected products
- Strapi strapi < 3.6.10
- Strapi @strapi/strapi 4.0.0-next.0 to < 4.1.10
Timeline
- 2021-12-09: disclosed: Vulnerability discovered
- 2022-05-11: patched: Security patches released in v3.6.10 and v4.1.10
- 2022-09-27: advisory: Public disclosure via CVE-2022-31367
- 2022-09-28: advisory: GHSA advisory published