The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
This vulnerability is being actively exploited in the wild, according to the CISA Known Exploited Vulnerabilities catalog. CISA added it on .
CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Identifier
- CVE-2023-22894
- Published
- Record updated
- Fixed in
- The source references a patch, a mitigation or a vendor advisory.
- EPSS
- 3.4%
Summary
CVE-2023-22894 is a cleartext storage of sensitive information flaw in Strapi. An attacker with access to the admin panel could discover sensitive user details through the query filter. The source notes it can be chained with CVE-2023-22621 to achieve remote code execution.
Mitigation
Users are advised to discontinue use of the affected product and/or transition to a supported version. Apply mitigations in accordance with vendor instructions and follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable.