Intel

AIKIDO-2024-10092

@strapi/strapi is vulnerable to URL Redirection to Untrusted Site ('Open Redirect')

URL Redirection to Untrusted Site ('Open Redirect') Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 10, 2024

80

High Risk

This Affects:

JS@strapi/strapi
4.0.0 - 4.24.1
Fixed in 4.24.2
Are you affected? Scan for Free

TL;DR

Affected versions of the @strapi/strapi library are vulnerable to open redirect. @strapi/strapi accepts user-controlled input that specifies a link to an external site and uses that link in a redirect. This vulnerability simplifies phishing attacks. The plugin configuration can be customized by the user and is not properly validated.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@strapi/strapi is vulnerable to URL Redirection to Untrusted Site ('Open Redirect') in versions 4.0.0 - 4.24.1.

How to fix this

Upgrade the @strapi/strapi library to the patch version.