Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where an item in the collection has an association to another collection. When this happens, another user with Author Role can see the list of associated items they did not create. They should see nothing but their own items they created not all items ever created. Users should upgrade @strapi/plugin-content-manager to version 4.19.1 to receive a patch.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-06-12T14:46:04.902Z

Updated: 2024-06-12T15:36:12.536Z

Reserved: 2024-03-18T17:07:00.092Z


Link: CVE-2024-29181

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-12T15:15:50.873

Modified: 2024-06-13T18:36:09.010


Link: CVE-2024-29181

JSON object: View

cve-icon Redhat Information

No data.

CWE