Vulnerabilities > CVE-2023-48218 - Incorrect Authorization vulnerability in Strapi Protected Populate

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
strapi
CWE-863

Summary

The Strapi Protected Populate Plugin protects `get` endpoints from revealing too much information. Prior to version 1.3.4, users were able to bypass the field level security. Users who tried to populate something that they didn't have access to could populate those fields anyway. This issue has been patched in version 1.3.4. There are no known workarounds.

Vulnerable Configurations

Part Description Count
Application
Strapi
1

Common Weakness Enumeration (CWE)