Логотип exploitDog
bind:CVE-2024-29181
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-29181

Количество 2

Количество 2

nvd логотип

CVE-2024-29181

больше 1 года назад

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.

CVSS3: 2.3
EPSS: Низкий
github логотип

GHSA-6j89-frxc-q26m

больше 1 года назад

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

CVSS3: 2.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-29181

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.

CVSS3: 2.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-6j89-frxc-q26m

@strapi/plugin-content-manager leaks data via relations via the Admin Panel

CVSS3: 2.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу