VDB
Sign up
HIGH7.5

GHSA-4hmq-ggrm-qfc6

directus vulnerable to HTML Injection in Password Reset email to custom Reset URL

Quick fix

GHSA-4hmq-ggrm-qfc6 — directus: upgrade to the fixed version with the command below.

npm install directus@9.23.0

Details

### Impact

Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL.

### Patches

The problem has been resolved and released under version 9.23.0. People relying on a custom password reset URL should upgrade to 9.23.0 or later, or remove the custom reset url from the configured allow list.

### Workarounds

Disable the custom reset URL allow list.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 9.23.0
Fixnpm install directus@9.23.0

References