Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2022-43430 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test
CVE-2013-4002 Vulnerability in maven package xerces:xercesimpl
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-font