Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-36641 Vulnerability in maven package fr.turri:axmlrpc
CVE-2020-26217 Vulnerability in maven package org.jvnet.hudson:xstream
CVE-2020-28248 Vulnerability in npm package png-img
CVE-2021-44228 Vulnerability in maven package org.apache.logging.log4j:log4j-core