HIGH
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses
Published Sep 27, 2022
8.8
HIGHCVSS 3.1
EPSS 1.68%
Description
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
strapi
npm
Introduced 0 Fixed 3.6.10@strapi/strapi
npm
Introduced 4.0.0-next.0 Fixed 4.1.10
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | strapi | 0 | 3.6.10 |
| npm | @strapi/strapi | 4.0.0-next.0 | 4.1.10 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6691 Advisory
- https://github.com/advisories/GHSA-4phg-hpqm-c3j4 Advisory
- https://github.com/kos0ng/CVEs/tree/main/CVE-2022-31367 x_refsource_MISCExploitThird Party Advisory
- https://github.com/strapi/strapi/pull/13185
- https://github.com/strapi/strapi/pull/13189
- https://github.com/strapi/strapi/releases/tag/v3.6.10 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/strapi/strapi/releases/tag/v4.1.10 x_refsource_MISCRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-31367
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6691 | Advisory | |
| https://github.com/advisories/GHSA-4phg-hpqm-c3j4 | Advisory | |
| https://github.com/kos0ng/CVEs/tree/main/CVE-2022-31367 | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/strapi/strapi/pull/13185 | ||
| https://github.com/strapi/strapi/pull/13189 | ||
| https://github.com/strapi/strapi/releases/tag/v3.6.10 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/strapi/strapi/releases/tag/v4.1.10 | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-31367 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 27, 2022
Updated May 22, 2025
Reserved May 23, 2022
Link CVE-2022-31367
CISA Vulnrichment
Updated May 22, 2025
Red Hat
No data
GitHub
Link GHSA-4PHG-HPQM-C3J4