Strapi's field level permissions not being respected in relationship title
- Severity:
- Medium
Description
Field level permissions not being respected in relationship title. If I have a relationship title and the relationship shows a field I don’t have permission to see I will still be visible.
Recommendation
Update the @strapi/plugin-content-manager
package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.12.1
- Patched version(s): 4.12.1
References
Related Issues
- @sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params - CVE-2025-32388
- MongoDB Shell may be susceptible to control character injection via pasting - CVE-2025-1692
- Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS - CVE-2024-45812
- ag-grid packages vulnerable to Prototype Pollution (GHSA-328p-362g-r48j) 2 - CVE-2024-39001
- Tags:
- npm
- @strapi/plugin-content-manager
Anything's wrong? Let us know Last updated on September 25, 2024