Advisories for Npm/@Strapi/Plugin-Content-Manager package

2024
2023

Strapi's field level permissions not being respected in relationship title

Summary Field level permissions not being respected in relationship title. If I have a relationship title and the relationship shows a field I don't have permission to see I will still be visible. Details No RBAC checks on on the relationship the relation endpoint returns PoC Setup Create a fresh strapi instance Create a new content type in the newly created content type add a relation to the users-permissions user. …