Rate limit bypass on auth routes due to invalid prefix checking
Strapi security advisories
All 21 advisories Strapi has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 2121 carry a CVE
- critical
- 4
- high
- 7
- medium
- 6
- low
- 4
- Fix in the archive
- 5of 21 matched to a release
- Oldest
- 18 Apr 20233.4 years ago
16 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productPassword Reset Does Not Revoke Existing Refresh Sessions
SQL Injection in Content Type Builder
Upload Plugin MIME Validation Bypass via Content API
Leaking sensitive data via relational filtering due to lack of query sanitization
Weak Password Length Validation
Unauthorized Access to Private Fields via parms.lookup
CORS Misconfiguration Leads to Sensitive Data Exposure
Server - Side Request Forgery in Webhook function
Leaking data via relations via the Admin Panel
Denial-of-Service via Improper Exception Handling
3rd party token leak and authentication bypass
Unauthorized Access to Private Fields in User Registration API
Improper Rate Limiting
Leaking sensitive user information, user reset password, tokens via content-manager views
Field level permissions not being respected in relationship title
Leaking sensitive user information still possible by filtering on private with prefix fields
Making all attributes on a content-type public via review workflows
Leaking sensitive user information by filtering on private fields
Authentication Bypass for AWS Cognito Login Provider
SSTI to RCE in the Users-Permissions Plugin