Strapi is an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure that they can't be selected. This issue is fixed in version 4.11.7.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/strapi/strapi/security/advisories/GHSA-v8gg-4mq2-88q4 | third party advisory exploit |
https://github.com/strapi/strapi/releases/tag/v4.11.7 | release notes |