CVE-2024-29181
low-risk
Published 2024-06-12
Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.
Do I need to act?
-
0.43% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
2
CVSS 2.3/10
Low
ADJACENT_NETWORK
/ HIGH complexity
Affected Products (1)
Affected Vendors
References (4)
13
/ 100
low-risk
Severity
6/34 · Minimal
Exploitability
2/34 · Minimal
Exposure
5/34 · Minimal