SB2023091375 - Improper access control in strapi



SB2023091375 - Improper access control in strapi

Published: September 13, 2023 Updated: April 23, 2026

Security Bulletin ID SB2023091375
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2023-36472)

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /content-manager/relations route when handling relation field selection in content-manager views. A remote user can select private fields and access user reset password tokens to disclose sensitive information.

User interaction is required, and exploitation requires configure view permissions.


Remediation

Install update from vendor's website.