Description
Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack increases. Version 4.12.1 has a fix for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2389 | Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack increases. Version 4.12.1 has a fix for this issue. |
Github GHSA |
GHSA-24q2-59hm-rh9r | Strapi Improper Rate Limiting vulnerability |
References
History
Wed, 25 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-25T18:05:58.465Z
Reserved: 2023-07-18T16:28:12.078Z
Link: CVE-2023-38507
Updated: 2024-08-02T17:46:55.754Z
Status : Modified
Published: 2023-09-15T20:15:08.997
Modified: 2024-11-21T08:13:43.200
Link: CVE-2023-38507
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA