CVE-2023-22894: Strapi Strapi
CISA (English)
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
- 廠商
- Strapi
- 產品
- Strapi
- 漏洞
- Strapi Cleartext Storage of Sensitive Information Vulnerability
- 加入日期
- 2026年10月8日
- CISA 修補期限(美國聯邦機關)
- 2026年10月11日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-312
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.08
關於本頁
Strapi包含一個敏感資訊脆弱性的清晰文字儲存,可以讓訪問管理員面板的攻擊者透過查詢過濾器發現敏感的使用者細節。受影響的產品(產品)可能是終身(EoL)和/或終身(EoS)。建議使用者停止使用和/或向支援的版本過渡。這種脆弱性可以與CVE-2023-22621連鎖,以實現遠端程式碼執行。