CVE-2024-34065
HIGHDescription
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and retrieve the 3rd party tokens. The attack requires user interaction (one click). Unauthenticated attackers can leverage two vulnerabilities to obtain an 3rd party token and the bypass authentication of Strapi apps. Users should upgrade @strapi/plugin-users-permissions to version 4.24.2 to receive a patch.
Is your site exposed to CVE-2024-34065?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| strapi | strapi |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-34065? +
How severe is CVE-2024-34065? +
What products are affected by CVE-2024-34065? +
How do I check if I'm vulnerable to CVE-2024-34065? +
Related Vulnerabilities
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process …
Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion …
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the …
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key …
Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a …
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the …