{"id":"GHSA-4phg-hpqm-c3j4","summary":"Strapi mishandles hidden attributes within admin API responses","details":"Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.","aliases":["CVE-2022-31367"],"modified":"2023-11-08T04:09:30.540882Z","published":"2022-09-28T00:00:17Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-09-30T05:17:55Z","nvd_published_at":"2022-09-27T23:15:00Z","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31367"},{"type":"WEB","url":"https://github.com/strapi/strapi/pull/13185"},{"type":"WEB","url":"https://github.com/strapi/strapi/pull/13189"},{"type":"WEB","url":"https://github.com/kos0ng/CVEs/tree/main/CVE-2022-31367"},{"type":"PACKAGE","url":"https://github.com/strapi/strapi"},{"type":"WEB","url":"https://github.com/strapi/strapi/releases/tag/v3.6.10"},{"type":"WEB","url":"https://github.com/strapi/strapi/releases/tag/v4.1.10"}],"affected":[{"package":{"name":"strapi","ecosystem":"npm","purl":"pkg:npm/strapi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.6.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-4phg-hpqm-c3j4/GHSA-4phg-hpqm-c3j4.json"}},{"package":{"name":"@strapi/strapi","ecosystem":"npm","purl":"pkg:npm/%40strapi/strapi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0-next.0"},{"fixed":"4.1.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-4phg-hpqm-c3j4/GHSA-4phg-hpqm-c3j4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}