Company
Date Published
June 12, 2024
Author
Derrick Mehaffy
Word count
1478
Language
English
Hacker News points
None

Summary

Three security vulnerabilities have been patched in the Strapi framework, including a Denial-of-Service issue, lax RBAC access control on fields rendering lists of relations, and an Open Redirect combined with transmission of session tokens via URL query parameters. The patches were released in version v4.24.2. Strapi has followed responsible disclosure practices by patching the vulnerabilities before full disclosure and notifying customers to upgrade their servers.