QID 995835
Date Published: 2023-11-06
QID 995835: NodeJs (Npm) Security Update for @strapi/plugin-users-permissions (GHSA-gc7p-j5xm-xxh2)
I marked some fields as private fields in user content-type, and tried to register as a new user via api, at the same time I added content to fill the private fields and sent a post request, and as you can see from the images below, I can write to the private fields.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-gc7p-j5xm-xxh2 for updates and patch information.
Vendor References
- GHSA-gc7p-j5xm-xxh2 -
github.com/advisories/GHSA-gc7p-j5xm-xxh2
CVEs related to QID 995835
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gc7p-j5xm-xxh2 | @strapi/plugin-users-permissions |
|