{"id":"CVE-2021-46440","aliases":["GHSA-85vg-grr5-pw42"],"url":"https://o3.security/vulnerability/CVE-2021-46440","summary":"Insecure password handling vulnerability in Strapi","details":"Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext password, leading to getting API documentation for further API attacks.","published":"2022-05-03T18:15:08.763Z","modified":"2026-07-09T01:25:08.969841Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.02839,"percentile":0.85982,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"strapi","fixedVersion":"3.6.9"},{"ecosystem":"npm","name":"@strapi/strapi","fixedVersion":"4.1.5"}],"fix":{"url":"https://github.com/strapi/strapi/pull/12246","label":"strapi/strapi#12246"},"references":[{"type":"ADVISORY","url":"https://hub.docker.com/r/strapi/strapi"},{"type":"ADVISORY","url":"https://strapi.io/"},{"type":"FIX","url":"https://github.com/strapi/strapi/pull/12246"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/166915/Strapi-3.6.8-Password-Disclosure-Insecure-Handling.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:25:08.969841Z"}}