KNOWN EXPLOITED VULNERABILITY DOSSIER
CVE-2023-22894
Strapi · Strapi
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
Correlated Federal Court Cases & Indictments (0)
No specific federal indictment in our landmark database directly links to this CVE yet. This vulnerability is monitored under CISA's Known Exploited Vulnerabilities catalog.
Associated Government Advisories
Direct advisory cross-references are being continuously mapped from CISA and allied CERT publications.