Description
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
Remediation
References
https://github.com/strapi/strapi/pull/8439
https://github.com/strapi/strapi/releases/tag/v3.2.5
Related Vulnerabilities
CVE-2021-4103 Vulnerability in npm package vditor
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-nio
CVE-2022-43414 Vulnerability in maven package org.jenkins-ci.plugins:nunit
CVE-2020-1960 Vulnerability in maven package org.apache.flink:flink-metrics-core
CVE-2016-0789 Vulnerability in maven package org.jenkins-ci.main:jenkins-core