npm›strapi-plugin-content-type-builder›CVE-2020-276657.5 HIGHIncorrect Default PermissionsIn Strapi, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.