First published: Thu Oct 22 2020(Updated: )
In Strapi before 3.2.5, there is no `admin::hasPermissions` restriction for CTB (aka content-type-builder) routes.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Strapi Strapi | <3.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27665 refers to a vulnerability in Strapi before version 3.2.5 where there is no admin::hasPermissions restriction for CTB (content-type-builder) routes.
CVE-2020-27665 has a severity rating of high, with a severity value of 7.5.
CVE-2020-27665 affects Strapi versions up to and excluding 3.2.5, as well as the Strapi Strapi CPE (Common Platform Enumeration).
To fix CVE-2020-27665, it is recommended to update to version 3.2.5 of the strapi-plugin-content-type-builder package.
More information about CVE-2020-27665 can be found at the following sources: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-27665), [GitHub Pull Request](https://github.com/strapi/strapi/pull/8439), [GitHub Commit](https://github.com/strapi/strapi/commit/3cdd73987950d5c7976701047b38203e902007bb).