Junglewise Threat Intelligence

CVE-2023-36472: Strapi information disclosure in content-manager relations view

CVE-2023-36472 · Severity: low · CVSS 3.1 · Published 2023-09-13

Technologies: Strapi Admin, @strapi/utils (npm), @strapi/plugin-content-manager (npm), @strapi/admin (npm). Vendors: Strapi, npm.

Executive brief

Strapi is a headless CMS platform used to manage and deliver content to applications. A vulnerability in the content-manager plugin allows users with limited administrative permissions (Author role with configure view access) to view sensitive fields like password reset tokens that should be private, potentially enabling account takeover of higher-privileged admin accounts.

Technical details

The vulnerability exists in the /content-manager/relations endpoint, which fails to filter out or restrict access to private fields when returning relation data. An attacker with Author role permissions and content-manager configure view access can craft requests to view admin user relations and access sensitive fields such as resetPasswordToken. The attack requires specific role configuration and user interaction but results in exposure of authentication tokens. This is a CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerability that allows privilege escalation by obtaining an admin's password reset token and changing their password. The vulnerability was fixed in version 4.11.7.

Affected products

  • Strapi Admin < 4.11.7
  • Strapi Content-Manager Plugin < 4.11.7
  • Strapi Utils < 4.11.7

Timeline

  • 2023-09-13: disclosed
  • 2023-09-13: patched: Version 4.11.7 released with fix

References

Related threats