CVE-2020-8123

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
04/02/2020
Last modified:
06/02/2020

Description

A denial of service exists in strapi v3.0.0-beta.18.3 and earlier that can be abused in the admin console using admin rights can lead to arbitrary restart of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:strapi:strapi:*:*:*:*:*:node.js:*:* 3.0.0 (excluding)
cpe:2.3:a:strapi:strapi:3.0.0:alpha10.1:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha10.2:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha10.3:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha11:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha11.1:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha11.2:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha11.3:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.1:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.1.3:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.2:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.3:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.4:*:*:*:node.js:*:*
cpe:2.3:a:strapi:strapi:3.0.0:alpha12.5:*:*:*:node.js:*:*


References to Advisories, Solutions, and Tools