## Overview
CISA has added CVE-2023-22894 to its Known Exploited Vulnerabilities (KEV) list. This move signals a federal deadline for organizations to address the issue. The vulnerability affects Strapi versions up to 4.5.5 and allows attackers to exploit sensitive user data through the admin panel.
## Technical Details
CVE-2023-22894 is a cleartext storage of sensitive information vulnerability. Attackers with admin panel access can use the query filter to discover sensitive user details. They can filter users by columns containing sensitive information and infer values from API responses. Super admin access allows attackers to uncover password hashes and password reset tokens for all users. Those with lower privileges can still access usernames and emails of API users, which increases the risk of data exposure.
## Impact
The vulnerability poses a significant risk to organizations using Strapi, especially if they have not upgraded to a supported version. The potential for data leaks is high, particularly for sensitive information that could be exploited in further attacks. The vulnerability can also be chained with CVE-2023-22621, leading to remote code execution, amplifying the threat landscape.
## Mitigation
Organizations should immediately upgrade Strapi to a version beyond 4.5.5 to mitigate this vulnerability. It is also advisable to review access controls for the admin panel and limit permissions to reduce the risk of exploitation. Users should monitor for any signs of unauthorized access and consider transitioning to supported software if currently using an end-of-life version.
CSURFACE Threat Sensor