Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2011-2526 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2021-41151 Vulnerability in npm package @backstage/plugin-scaffolder-backend
CVE-2020-28441 Vulnerability in npm package conf-cfg-ini
CVE-2021-32050 Vulnerability in maven package org.webjars.npm:mongodb
CVE-2021-21364 Vulnerability in maven package io.swagger:swagger-codegen