Exploited Vulnerabilities Daily
🌐 日本語

CVE-2023-22894: Strapi Strapi

CISA (English)

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

ベンダー
Strapi
製品
Strapi
脆弱性
Strapi Cleartext Storage of Sensitive Information Vulnerability
追加日
2026/10/08
CISA対応期限(米国連邦機関向け)
2026/10/11
ランサムウェア攻撃での利用
不明
弱点(CWE)
CWE-312

参考情報

当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。

最終更新: · カタログのバージョン 2026.10.08

このページについて

ストラップには、攻撃者が管理者パネルにアクセスして、クエリフィルタを介して機密ユーザーの詳細を発見できるようにする、機密情報脆弱性の明確なテキストストレージが含まれています。インパクトのある製品(s)は、エンド・オブ・ライフ(EoL)および/またはエンド・オブ・サービス(EoS)である可能性があります。ユーザーは、サポートされたバージョンへの使用および/または移行を中止することを推奨します。この脆弱性は、CVE-2023-22621 と連携して、リモートコードの実行を実現することができます。