Junglewise Threat Intelligence

CVE-2023-37263: Strapi field level permissions bypass in relationship title

CVE-2023-37263 · Severity: low · CVSS 3.1 · Published 2023-09-13

Technologies: @strapi/plugin-content-manager (npm). Vendors: Strapi, npm.

Executive brief

Strapi is a headless CMS used to manage and serve content to applications. A flaw in how the system enforces role-based access controls (RBAC) allows an authenticated admin user with restricted permissions to view sensitive data fields they should not have access to when those fields are displayed as relationship titles. This could leak confidential information selected by administrators, such as user details or other protected fields, to users with limited roles.

Technical details

This vulnerability is an authorization bypass in the @strapi/plugin-content-manager package where field-level RBAC checks are not properly enforced on relationship endpoints. An attacker with high-privilege credentials (an admin account) but restricted field-level permissions can navigate the content manager to view relationship data and observe fields that their role explicitly denies access to. The vulnerability requires network access and authenticated admin credentials with at least partial role permissions. An authenticated user with low privileges can thus bypass field-level access controls to read sensitive data displayed in relationship titles. The issue is fixed in version 4.12.1 and later.

Affected products

  • Strapi @strapi/plugin-content-manager <= 4.12.0

Timeline

  • 2023-09-13: disclosed
  • 2023-09-13: patched: Version 4.12.1 released with fix

References

Related threats