GHSA-85vg-grr5-pw42
Dashboard / Vulnerabilities / GHSA-85vg-grr5-pw42
Summary: Insecure password handling vulnerability in Strapi
Details: Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request. From this, the attacker can get the victim's cookie, base64 decode it, and obtain a cleartext password, leading to getting API documentation for further API attacks.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-46440, https://github.com/strapi/strapi/pull/12246, https://github.com/strapi/strapi, https://hub.docker.com/r/strapi/strapi, https://strapi.io, http://packetstormsecurity.com/files/166915/Strapi-3.6.8-Password-Disclosure-Insecure-Handling.html
Affected packages
Package
Name: strapi
Purl: pkg:npm/strapi
Affected ranges
Type: SEMVER
Events:
