GHSA-4phg-hpqm-c3j4

Suggest an improvement
Source
https://github.com/advisories/GHSA-4phg-hpqm-c3j4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-4phg-hpqm-c3j4/GHSA-4phg-hpqm-c3j4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4phg-hpqm-c3j4
Aliases
Published
2022-09-28T00:00:17Z
Modified
2023-11-08T04:09:30.540882Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Strapi mishandles hidden attributes within admin API responses
Details

Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.

Database specific
{
    "nvd_published_at": "2022-09-27T23:15:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2022-09-30T05:17:55Z",
    "cwe_ids": [
        "CWE-89"
    ],
    "github_reviewed": true
}
References

Affected packages

npm / strapi

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-4phg-hpqm-c3j4/GHSA-4phg-hpqm-c3j4.json"

npm / @strapi/strapi

Package

Name
@strapi/strapi
View open source insights on deps.dev
Purl
pkg:npm/%40strapi/strapi

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-next.0
Fixed
4.1.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-4phg-hpqm-c3j4/GHSA-4phg-hpqm-c3j4.json"