Vulnerabilities/

Improper Removal of Sensitive Information Before Storage or Transfer in Strapi

Severity:
High

Description

An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions).

Recommendation

Update the @strapi/strapi package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/strapi
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing