CVE-2020-27665: High severity strapi vulnerability
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Other sources
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27665?
CVE-2020-27665 refers to a vulnerability in Strapi before version 3.2.5 where there is no admin::hasPermissions restriction for CTB (content-type-builder) routes.
How severe is CVE-2020-27665?
CVE-2020-27665 has a severity rating of high, with a severity value of 7.5.
What software is affected by CVE-2020-27665?
CVE-2020-27665 affects Strapi versions up to and excluding 3.2.5, as well as the Strapi Strapi CPE (Common Platform Enumeration).
How can I fix CVE-2020-27665?
To fix CVE-2020-27665, it is recommended to update to version 3.2.5 of the strapi-plugin-content-type-builder package.
Where can I find more information about CVE-2020-27665?
More information about CVE-2020-27665 can be found at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-27665), [GitHub Pull Request](https://github.com/strapi/strapi/pull/8439), [GitHub Commit](https://github.com/strapi/strapi/commit/3cdd73987950d5c7976701047b38203e902007bb).