Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2022-31160 Vulnerability in maven package org.webjars:jquery-ui
CVE-2020-15170 Vulnerability in maven package com.ctrip.framework.apollo:apollo-adminservice
CVE-2020-7640 Vulnerability in npm package pixl-class
CVE-2020-11612 Vulnerability in maven package io.netty:netty-codec
CVE-2022-31129 Vulnerability in maven package org.webjars.bowergithub.moment:moment