HIGH7.5
GHSA-85vg-grr5-pw42
Insecure password handling vulnerability in Strapi
Quick fix
GHSA-85vg-grr5-pw42 — strapi: upgrade to the fixed version with the command below.
npm install strapi@3.6.9Details
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request. From this, the attacker can get the victim's cookie, base64 decode it, and obtain a cleartext password, leading to getting API documentation for further API attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-46440[ADVISORY]
- https://github.com/strapi/strapi/pull/12246[WEB]
- https://github.com/strapi/strapi[PACKAGE]
- https://hub.docker.com/r/strapi/strapi[WEB]
- https://strapi.io[WEB]
- http://packetstormsecurity.com/files/166915/Strapi-3.6.8-Password-Disclosure-Insecure-Handling.html[WEB]