Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2023-27474 Vulnerability in npm package directus
CVE-2020-36380 Vulnerability in npm package aaptjs
CVE-2021-41174 Vulnerability in npm package @grafana/data
CVE-2021-3461 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-37959 Vulnerability in maven package org.jenkins-ci.plugins:sumologic-publisher