Beveiligingsadvies

CVE-2024-29181

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-06-12 14:46:04
Laatst bijgewerkt 2024-08-02 01:10:54
Toegewezen door GitHub_M
CVSS-score 2.3
Status PUBLISHED

Beschrijving

Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.