VDB
Sign up
MEDIUM4.3

GHSA-cph6-524f-3hgr

Directus Vulnerable to Information Leakage in Existing Collections

Quick fix

GHSA-cph6-524f-3hgr — directus: upgrade to the fixed version with the command below.

npm install directus@11.13.0

Details

### Summary:

An observable difference in error messaging was found in the Directus REST API. The `/items/{collection}` API returns different error messages for these two cases: 1. A user tries to access an existing collection which they are not authorized to access. 2. A user tries to access a non-existing collection.

The two differing error messages leak the existence of collections to users which are not authorized to access these collections.

### Details:

The following response returns an error message, when requesting a collection the user is not authorized to access.

``` GET /items/no-access { "errors": [ { "message": "You don't have permission to access collection \"no-access\" or it does not exist. Queried in root.", "extensions": { "reason": "You don't have permission to access collection \"no-access\" or it does not exist. Queried in root.", "code": "FORBIDDEN" } } ] } ```

The following response returns a different error message when requesting a collection which does not exist.

``` GET /items/does-not-exist { "errors": [ { "message": "You don't have permission to access this.", "extensions": { "code": "FORBIDDEN" } } ] } ```

### Impact:

The difference in errors between non-existent collections and collections blocked by permissions leak the existence of a collection to a user which is not authorized to access this object.

### Credit:

Sebastian Krause - [Hackmanit GmbH](https://hackmanit.de)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 11.13.0
Fixnpm install directus@11.13.0
npm/@directus/api
Introduced in: 0Fixed in: 32.0.0
Fixnpm install @directus/api@32.0.0

References