Vulnerability Issue

System Information
  • Strapi Version: 3.6.0
  • Operating System:
  • Database: MySQL
  • Node Version:
  • NPM Version:
  • Yarn Version:

Hi,

In Strapi through 3.6.0, the admin panel allows the changing of one’s own password without entering the current password. An attacker who gains access to a valid session can use this to take over an account by changing the password. Find more details in the CVE-2021-28128 : In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current pas

Is this issue fixed any of Strapi latest version & may I know the version details with change logs so that i can upgrade the same.

Thanks and regards
M Venkatesan

In my opinion this is quite expected behaviour. :thinking:

I would agree if you forgot the password but not changing his own password & the link which I have provided shows the high risk…

https://nvd.nist.gov/vuln/detail/CVE-2021-28128