CVE-2020-27664: Critical severity strapi vulnerability
Published Oct 22, 2020
·Updated
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
Other sources
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
Affected Software
2 affected componentsFixes available
npm/strapi<3.2.5
3.2.5
Strapi Strapi<3.2.5
Remediation
Patch Available
Event History
Oct 22, 2020
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
Description
May 10, 2021
Advisory Published
06:43 PM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-27664.
2
What is the severity of CVE-2020-27664?
The severity of CVE-2020-27664 is critical with a CVSS score of 9.8.
3
What is the affected software version?
The affected software version is Strapi before 3.2.5.
4
What is the description of CVE-2020-27664?
`admin/src/containers/InputModalStepperProvider/index.js` in Strapi before 3.2.5 has unwanted `/proxy?url=` functionality.
5
How can I fix CVE-2020-27664?
CVE-2020-27664 can be fixed by upgrading to Strapi version 3.2.5 or later.