Executive brief
Strapi is a headless CMS platform used to manage and deliver content to applications. A vulnerability in the content-manager plugin allows users with limited administrative permissions (Author role with configure view access) to view sensitive fields like password reset tokens that should be private, potentially enabling account takeover of higher-privileged admin accounts.
Technical details
The vulnerability exists in the /content-manager/relations endpoint, which fails to filter out or restrict access to private fields when returning relation data. An attacker with Author role permissions and content-manager configure view access can craft requests to view admin user relations and access sensitive fields such as resetPasswordToken. The attack requires specific role configuration and user interaction but results in exposure of authentication tokens. This is a CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerability that allows privilege escalation by obtaining an admin's password reset token and changing their password. The vulnerability was fixed in version 4.11.7.
Affected products
- Strapi Admin < 4.11.7
- Strapi Content-Manager Plugin < 4.11.7
- Strapi Utils < 4.11.7
Timeline
- 2023-09-13: disclosed
- 2023-09-13: patched: Version 4.11.7 released with fix