Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack increases. Version 4.12.1 has a fix for this issue.
References
Link | Resource |
---|---|
https://github.com/strapi/strapi/blob/32d68f1f5677ed9a9a505b718c182c0a3f885426/packages/core/admin/server/middlewares/rateLimit.js#L31 | Issue Tracking |
https://github.com/strapi/strapi/releases/tag/v4.12.1 | Release Notes |
https://github.com/strapi/strapi/security/advisories/GHSA-24q2-59hm-rh9r | Exploit Third Party Advisory |
Configurations
History
21 Sep 2023, 14:09
Type | Values Removed | Values Added |
---|---|---|
First Time |
Strapi strapi
Strapi |
|
CPE | cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://github.com/strapi/strapi/security/advisories/GHSA-24q2-59hm-rh9r - Exploit, Third Party Advisory | |
References | (MISC) https://github.com/strapi/strapi/releases/tag/v4.12.1 - Release Notes | |
References | (MISC) https://github.com/strapi/strapi/blob/32d68f1f5677ed9a9a505b718c182c0a3f885426/packages/core/admin/server/middlewares/rateLimit.js#L31 - Issue Tracking |
17 Sep 2023, 12:01
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-15 20:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-38507
Mitre link : CVE-2023-38507
CVE.ORG link : CVE-2023-38507
JSON object : View
Products Affected
strapi
- strapi
CWE
CWE-770
Allocation of Resources Without Limits or Throttling