Exploited Vulnerabilities Daily
🌐 한국어

CVE-2023-22894: Strapi Strapi

CISA (English)

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.

공급업체
Strapi
제품
Strapi
취약점
Strapi Cleartext Storage of Sensitive Information Vulnerability
추가일
2026. 10. 8.
CISA 조치 기한(미국 연방기관)
2026. 10. 11.
랜섬웨어 공격 악용
알 수 없음
약점(CWE)
CWE-312

참고 자료

이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.

최종 업데이트: · 카탈로그 버전 2026.10.08

이 페이지에 대해

Strapi는 쿼리 필터를 통해 민감한 사용자 정보를 발견하기 위해 관리자 패널에 액세스하여 공격자를 허용 할 수있는 민감한 정보 취약점의 cleartext 스토리지를 포함합니다. 충격 제품 (s)는 end-of-life (EoL) 및/또는 end-of-service (EoS)일 수 있었습니다. 사용자는 지원되는 버전으로 사용 및/또는 전환을 중단하는 것이 좋습니다. 이 취약점은 원격 코드 실행을 달성하기 위해 CVE-2023-22621로 체인질 할 수 있습니다.