#VU126965 Uncaught Exception in strapi - CVE-2024-31217

 

#VU126965 Uncaught Exception in strapi - CVE-2024-31217

Published: June 12, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU126965
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2024-31217
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
strapi
Software vendor:
strapi.io

Description

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncaught exception in the media upload process when handling a crafted file upload request. A remote user can send a specially crafted upload request containing a null byte in the filename extension to cause a denial of service.

The issue affects both development and production environments and causes the server to remain unavailable until it is manually restarted.


Remediation

Install security update from vendor's website.

External links