CVE-2024-34065
HIGHDescription
Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before version 4.24.2, is its possible of an unauthenticated attacker to bypass authentication mechanisms and retrieve the 3rd party tokens. The attack requires user interaction (one click). Unauthenticated attackers can leverage two vulnerabilities to obtain an 3rd party token and the bypass authentication of Strapi apps. Users should upgrade @strapi/plugin-users-permissions to version 4.24.2 to receive a patch.
Is your site exposed to CVE-2024-34065?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| strapi | strapi |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-34065? +
How severe is CVE-2024-34065? +
What products are affected by CVE-2024-34065? +
How do I check if I'm vulnerable to CVE-2024-34065? +
Related Vulnerabilities
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the …
Transmitted data is logged between the device and the backend service. An attacker could use these logs to perform a …
Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the …
A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the user authentication process …
SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with …
Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key …