CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

Summary

Strapi has a cleartext storage of sensitive information vulnerability that allows attackers with admin panel access to uncover sensitive user details. This vulnerability can be combined with CVE-2023-22621 for remote code execution. Users are advised to transition to supported versions or apply vendor-provided mitigations.

IFF Assessment

FOE

This vulnerability allows attackers to access sensitive information, posing a risk to user data and system security.

Severity

7.2 High

CISA KEV: Listed as actively exploited. Federal patch due: October 11, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability highlights the risks of storing sensitive information in cleartext and the importance of applying security updates promptly. Defenders should prioritize patching Strapi instances, especially those with administrative access, and be aware of chained exploits that can lead to full system compromise.

Read Full Story →