GHSA-gc7p-j5xm-xxh2

Suggest an improvement
Source
https://github.com/advisories/GHSA-gc7p-j5xm-xxh2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-gc7p-j5xm-xxh2/GHSA-gc7p-j5xm-xxh2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gc7p-j5xm-xxh2
Aliases
Published
2023-11-03T19:01:11Z
Modified
2023-11-08T04:13:13Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Unauthorized Access to Private Fields in User Registration API
Details

System Details

Name Value
OS Windows 11
Version 4.11.1 (node v16.14.2)
Database mysql

Description

I marked some fields as private fields in user content-type, and tried to register as a new user via api, at the same time I added content to fill the private fields and sent a post request, and as you can see from the images below, I can write to the private fields.

register

user

private_field

table

To prevent this, I went to the extension area and tried to extend the register method, for this I wanted to do it using the sanitizeInput function that I know in the source codes of the strap. But the sanitizeInput function did not filter out private fields.

  const { auth } = ctx.state;
  const data = ctx.request.body;
  const userSchema = strapi.getModel("plugin::users-permissions.user");

  sanitize.contentAPI.input(data, userSchema, { auth });

here's the solution I've temporarily kept to myself, code snippet

  const body = ctx.request.body;

  const { attributes } = strapi.getModel("plugin::users-permissions.user");

  const sanitizedData = _.omitBy(body, (data, key) => {
    const attribute = attributes[key];

    if (_.isNil(attribute)) {
      return false;
    }

    //? If you want, you can throw an error for fields that we did not expect.

    // if (_.isNil(attribute))
    //   throw new ApplicationError(`Unexpected value ${key}`);

    // if private value is true, we do not want to send it to the database.
    return attribute.private;
  });

  return sanitizedData;
Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-11-03T19:01:11Z",
    "nvd_published_at":  "2023-11-06T19:15:09Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @strapi/plugin-users-permissions

Package

Name
@strapi/plugin-users-permissions
View open source insights on deps.dev
Purl
pkg:npm/%40strapi/plugin-users-permissions

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.13.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-gc7p-j5xm-xxh2/GHSA-gc7p-j5xm-xxh2.json"

npm / @strapi/strapi

Package

Name
@strapi/strapi
View open source insights on deps.dev
Purl
pkg:npm/%40strapi/strapi

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.13.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-gc7p-j5xm-xxh2/GHSA-gc7p-j5xm-xxh2.json"