VDB
Sign up
HIGH7.5

GHSA-85vg-grr5-pw42

Insecure password handling vulnerability in Strapi

Quick fix

GHSA-85vg-grr5-pw42 — strapi: upgrade to the fixed version with the command below.

npm install strapi@3.6.9

Details

Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request. From this, the attacker can get the victim's cookie, base64 decode it, and obtain a cleartext password, leading to getting API documentation for further API attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/strapi
Introduced in: 0Fixed in: 3.6.9
Fixnpm install strapi@3.6.9
npm/@strapi/strapi
Introduced in: 4.0.0Fixed in: 4.1.5
Fixnpm install @strapi/strapi@4.1.5

References