Check Point Advisories

Strapi Authentication Bypass (CVE-2019-18818)

Check Point Reference: CPAI-2019-3140
Date Published: 18 Jan 2024
Severity: Critical
Last Updated: Thursday 18 January, 2024
Source:
Industry Reference:CVE-2019-18818
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Strapi 1.6.4 and prior
Strapi 3.0.0 Alpha 10.1
Strapi 3.0.0 Alpha 10.2
Strapi 3.0.0 Alpha 10.3
Strapi 3.0.0 Alpha 11
Strapi 3.0.0 Alpha 11.1
Strapi 3.0.0 Alpha 11.2
Strapi 3.0.0 Alpha 11.3
Strapi 3.0.0 Alpha 12
Strapi 3.0.0 Alpha 12.1
Strapi 3.0.0 Alpha 12.1.3
Strapi 3.0.0 Alpha 12.2
Strapi 3.0.0 Alpha 12.3
Strapi 3.0.0 Alpha 12.4
Strapi 3.0.0 Alpha 12.5
Strapi 3.0.0 Alpha 12.6
Strapi 3.0.0 Alpha 12.7
Strapi 3.0.0 Alpha 12.7.1
Strapi 3.0.0 Alpha 13
Strapi 3.0.0 Alpha 13.0.1
Strapi 3.0.0 Alpha 13.1
Strapi 3.0.0 Alpha 14
Strapi 3.0.0 Alpha 14.1
Strapi 3.0.0 Alpha 14.1.1
Strapi 3.0.0 Alpha 14.2
Strapi 3.0.0 Alpha 14.3
Strapi 3.0.0 Alpha 14.4.0
Strapi 3.0.0 Alpha 14.5
Strapi 3.0.0 Alpha 15
Strapi 3.0.0 Alpha 16
Strapi 3.0.0 Alpha 17
Strapi 3.0.0 Alpha 18
Strapi 3.0.0 Alpha 19
Strapi 3.0.0 Alpha 20
Strapi 3.0.0 Alpha 21
Strapi 3.0.0 Alpha 22
Strapi 3.0.0 Alpha 23
Strapi 3.0.0 Alpha 23.1
Strapi 3.0.0 Alpha 24
Strapi 3.0.0 Alpha 24.1
Strapi 3.0.0 Alpha 25
Strapi 3.0.0 Alpha 25.1
Strapi 3.0.0 Alpha 25.2
Strapi 3.0.0 Alpha 26
Strapi 3.0.0 Alpha 26.1
Strapi 3.0.0 Alpha 26.2
Strapi 3.0.0 Alpha 4
Strapi 3.0.0 Alpha 4.8
Strapi 3.0.0 Alpha 5.3
Strapi 3.0.0 Alpha 5.5
Strapi 3.0.0 Alpha 6.3
Strapi 3.0.0 Alpha 6.4
Strapi 3.0.0 Alpha 6.7
Strapi 3.0.0 Alpha 7.2
Strapi 3.0.0 Alpha 7.3
Strapi 3.0.0 Alpha 8
Strapi 3.0.0 Alpha 8.3
Strapi 3.0.0 Alpha 9
Strapi 3.0.0 Alpha 9.1
Strapi 3.0.0 Alpha 9.2
Strapi 3.0.0 Beta 0
Strapi 3.0.0 Beta 1
Strapi 3.0.0 Beta 10
Strapi 3.0.0 Beta 11
Strapi 3.0.0 Beta 12
Strapi 3.0.0 Beta 13
Strapi 3.0.0 Beta 14
Strapi 3.0.0 Beta 15
Strapi 3.0.0 Beta 16
Strapi 3.0.0 Beta 16.1
Strapi 3.0.0 Beta 16.2
Strapi 3.0.0 Beta 16.3
Strapi 3.0.0 Beta 16.4
Strapi 3.0.0 Beta 16.5
Strapi 3.0.0 Beta 16.6
Strapi 3.0.0 Beta 16.7
Strapi 3.0.0 Beta 16.8
Strapi 3.0.0 Beta 17
Strapi 3.0.0 Beta 17.1
Strapi 3.0.0 Beta 17.2
Strapi 3.0.0 Beta 17.3
Strapi 3.0.0 Beta 17.4
Strapi 3.0.0 Beta 2
Strapi 3.0.0 Beta 3
Strapi 3.0.0 Beta 4
Strapi 3.0.0 Beta 5
Strapi 3.0.0 Beta 6
Strapi 3.0.0 Beta 7
Strapi 3.0.0 Beta 8
Strapi 3.0.0 Beta 9
Vulnerability Description An authentication bypass vulnerability exists in Strapi. Successful exploitation of this vulnerability would allow remote attackers to gain unauthorized access into the affected system.

Protection Overview

This protection detects attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R81 / R80 / R77 / R75

  1. In the IPS tab, click Protections and find the Strapi Authentication Bypass (CVE-2019-18818) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Web Server Enforcement Violation.
Attack Information:  Strapi Authentication Bypass (CVE-2019-18818)

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK