Cleartext Storage of Sensitive Data in Strapi (CVE‑2023‑22894) Risks Admin‑Panel Confidentiality
What It Is – Strapi’s headless‑CMS stores certain user details in cleartext within the admin database. An attacker who can log into the admin console can retrieve those details via a crafted query filter.
Exploitability – The flaw is publicly disclosed (CVE‑2023‑22894) and can be combined with CVE‑2023‑22621 to achieve remote code execution. No public exploit code has been released, but the vulnerability is rated High (CVSS ≈ 8.8) and is actively being scanned for.
Affected Products – Strapi open‑source CMS (all versions up to the latest 4.x that are no longer supported).
Why It Matters for Trust & Control Assurance
- Data‑at‑rest protection – Cleartext storage violates the control objective of encrypting sensitive information, a requirement across SOC 2, ISO 27001, NIST CSF and many regulatory regimes.
- Audit evidence – Demonstrating that sensitive fields are encrypted is a concrete piece of evidence auditors request; a gap here weakens the organization’s defensible audit trail.
- Continuous monitoring – Detecting unencrypted fields through automated configuration scans supports a continuous‑control‑monitoring posture that enterprise buyers now expect.
Recommended Actions
- Inventory all Strapi instances and verify the version; retire any end‑of‑life deployments.
- Enable encryption for all database columns that store personally identifiable information (PII) or other sensitive data.
- Patch to the latest supported Strapi release that addresses CVE‑2023‑22894 and CVE‑2023‑22621.
- Run a configuration audit (e.g., using Verisq’s Control Mapping module) to confirm no other cleartext fields remain.
- Update admin‑access policies – enforce MFA and least‑privilege roles for the Strapi admin console.
Source: CISA KEV – CVE‑2023‑22894