CVE-2022-31367: SQL Injection
Published Sep 27, 2022
·Updated
Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
Affected Software
2 affected components
Strapi Strapi<3.6.10
Strapi Strapi>=4.0.0<4.1.10
Event History
Sep 27, 2022
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-31367.
2
What is the severity of CVE-2022-31367?
The severity of CVE-2022-31367 is high, with a severity value of 8.8.
3
What software versions are affected by CVE-2022-31367?
CVE-2022-31367 affects Strapi versions before 3.6.10 and 4.x before 4.1.10.
4
How does CVE-2022-31367 mishandle hidden attributes within admin API responses?
CVE-2022-31367 mishandles hidden attributes within admin API responses in Strapi before 3.6.10 and 4.x before 4.1.10.
5
How can I fix CVE-2022-31367?
To fix CVE-2022-31367, you should upgrade your Strapi to version 3.6.10 or above for 3.x versions, or to version 4.1.10 or above for 4.x versions.