HIGH7.5
GHSA-4hmq-ggrm-qfc6
directus vulnerable to HTML Injection in Password Reset email to custom Reset URL
Quick fix
GHSA-4hmq-ggrm-qfc6 — directus: upgrade to the fixed version with the command below.
npm install directus@9.23.0Details
### Impact
Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL.
### Patches
The problem has been resolved and released under version 9.23.0. People relying on a custom password reset URL should upgrade to 9.23.0 or later, or remove the custom reset url from the configured allow list.
### Workarounds
Disable the custom reset URL allow list.
Are you affected?
Enter the version of the package you're using.