VulnerabilityModified
CVE-2023-38507
Therefore, the possibility of unauthorized login by login brute force attack increases.
CRITICAL 9.8EPSS 0.76%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Strapi is the an open-source headless content management system. Prior to version 4.12.1, there is a rate limit on the login function of Strapi's admin screen, but it is possible to circumvent it. Therefore, the possibility of unauthorized login by login brute force attack increases. Version 4.12.1 has a fix for this issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- strapi/strapi
- Source
- security-advisories@github.com
References
- https://github.com/strapi/strapi/blob/32d68f1f5677ed9a9a505b718c182c0a3f885426/packages/core/admin/server/middlewares/rateLimit.js#L31Issue Tracking
- https://github.com/strapi/strapi/releases/tag/v4.12.1Release Notes
- https://github.com/strapi/strapi/security/advisories/GHSA-24q2-59hm-rh9rExploit, Third Party Advisory
- https://github.com/strapi/strapi/blob/32d68f1f5677ed9a9a505b718c182c0a3f885426/packages/core/admin/server/middlewares/rateLimit.js#L31Issue Tracking
- https://github.com/strapi/strapi/releases/tag/v4.12.1Release Notes
- https://github.com/strapi/strapi/security/advisories/GHSA-24q2-59hm-rh9rExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.