Executive brief
Strapi, a popular content management system, contains a flaw in how it handles login security. Attackers can bypass the system's rate-limiting protections, which are designed to prevent automated password guessing. This increases the risk of unauthorized access to the administrative dashboard through brute-force attacks.
Technical details
An improper rate limiting vulnerability exists in Strapi's admin login functionality due to inconsistent path normalization in the rate-limiting middleware. The middleware uses the raw request path (ctx.request.path) as part of the cache key for tracking attempts. An attacker can bypass the limit by varying the casing of the URL (e.g., /admin/Login vs /admin/login) or by appending trailing slashes (e.g., /admin/login/). This allows for high-frequency brute-force attacks against administrative credentials. The issue is resolved in version 4.12.1 by normalizing request paths to lowercase and stripping trailing slashes before processing rate limits.
Affected products
- Strapi @strapi/admin <= 4.12.0
- Strapi @strapi/plugin-users-permissions <= 4.12.0
Timeline
- 2023-08-02: patched: Version 4.12.1 released
- 2023-09-13: disclosed: GitHub Advisory published
- 2023-09-15: advisory: NVD published CVE-2023-38507