GHSA-37hx-4mcq-wc3h

Suggest an improvement
Source
https://github.com/advisories/GHSA-37hx-4mcq-wc3h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-37hx-4mcq-wc3h/GHSA-37hx-4mcq-wc3h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-37hx-4mcq-wc3h
Aliases
Published
2021-10-06T17:48:16Z
Modified
2023-11-08T04:05:28Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Weak Password Recovery Mechanism for Forgotten Password in Strapi
Details

In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password.

Database specific
{
    "cwe_ids":  [
        "CWE-640"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-10-06T14:09:30Z",
    "nvd_published_at":  "2021-05-06T14:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / strapi

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-37hx-4mcq-wc3h/GHSA-37hx-4mcq-wc3h.json"