Executive brief
Strapi's Content Manager plugin is a tool used to manage and organize website content in a CMS system. A flaw in the plugin allows lower-privilege users (Authors) to see sensitive data created by administrators when they create new content with relationships to protected collections. This could expose passwords, emails, and other confidential information that should only be visible to admin users.
Technical details
The vulnerability is an authorization/data disclosure flaw (CWE-639) in the @strapi/plugin-content-manager where role-based access controls are not properly enforced when displaying related collection items in dropdown menus. When an Author-role user creates a new item in a private collection that has associations to another private collection, the dropdown shows all items from the associated collection—including those created by administrators—instead of showing only items the Author user created. The attack requires an authenticated Author account, user interaction (creating an item and expanding the dropdown), and adjacent network access to the admin panel. An attacker can view protected data they should not have access to. The vulnerability affects all versions up to 4.19.0 and is fixed in 4.19.1.
Affected products
- Strapi Content Manager <=4.19.0
Timeline
- 2024-06-12: disclosed
- 2024-06-12: patched: Version 4.19.1 fixes the vulnerability
- 2024-06-12: advisory