V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2024-34065
ANC
High

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL que…

CVSS
8.1
High
EPSS
0.01
p48
Published
2024-01-01
Updated
2024-01-01
Description

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and retrieve the 3rd party tokens. The attack requires user interaction (one click). Unauthenticated attackers can leverage two vulnerabilities to obtain an 3rd party token and the bypass authentication of Strapi apps. Users should upgrade @strapi/plugin-users-permissions to version 4.24.2 to receive a patch.

Tags · CWE
Pre-auth
CWE-294
CAPEC-60
CAPEC-94
CAPEC-102
CAPEC-509
CAPEC-555
CAPEC-561
CAPEC-644
CAPEC-645
CAPEC-652
CAPEC-701
Affected products
Strapi < 4.24.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.007 · p48
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-294
└ via CAPEC-561 · CWE-294
└ via CAPEC-555 · CWE-294
└ via CAPEC-555 · CWE-294
└ via CAPEC-60 · CWE-294
└ via CAPEC-644 · CWE-294
└ via CAPEC-645 · CWE-294
└ via CAPEC-60 · CWE-294
└ via CAPEC-94 · CWE-294
└ via CAPEC-652 · CWE-294
└ via CAPEC-509 · CWE-294
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
strapi*Tracked
Source databases
ANC
CVE