CVE-2023-22894: Strapi Strapi
CISA (English)
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
- ベンダー
- Strapi
- 製品
- Strapi
- 脆弱性
- Strapi Cleartext Storage of Sensitive Information Vulnerability
- 追加日
- 2026/10/08
- CISA対応期限(米国連邦機関向け)
- 2026/10/11
- ランサムウェア攻撃での利用
- 不明
- 弱点(CWE)
- CWE-312
参考情報
当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。
最終更新: · カタログのバージョン 2026.10.08
このページについて
ストラップには、攻撃者が管理者パネルにアクセスして、クエリフィルタを介して機密ユーザーの詳細を発見できるようにする、機密情報脆弱性の明確なテキストストレージが含まれています。インパクトのある製品(s)は、エンド・オブ・ライフ(EoL)および/またはエンド・オブ・サービス(EoS)である可能性があります。ユーザーは、サポートされたバージョンへの使用および/または移行を中止することを推奨します。この脆弱性は、CVE-2023-22621 と連携して、リモートコードの実行を実現することができます。