Vulnerabilities > CVE-2024-29181 - Authorization Bypass Through User-Controlled Key vulnerability in Strapi
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/strapi/strapi/commit/e1dfd4d9f1cab25cf6da3614c1975e4e508e01c6
- https://github.com/strapi/strapi/commit/e1dfd4d9f1cab25cf6da3614c1975e4e508e01c6
- https://github.com/strapi/strapi/security/advisories/GHSA-6j89-frxc-q26m
- https://github.com/strapi/strapi/security/advisories/GHSA-6j89-frxc-q26m