GHSA-m5q3-8wgf-x8xf
Directus vulnerable to extraction of password hashes through export querying
Quick fix
GHSA-m5q3-8wgf-x8xf — directus: upgrade to the fixed version with the command below.
npm install directus@9.16.0Details
### Impact
Users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by brute forcing the export functionality combined with a `_starts_with` filter. This allows the user to enumerate the password hashes.
### Patches
The problem has been patched by preventing any hashed/concealed field to be filtered against with the `_starts_with` or other string operator.
### Workarounds
Ensuring that no user has `read` access to the `password` field in `directus_users` is sufficient to prevent this vulnerability.
### For more information If you have any questions or comments about this advisory: * Open a Discussion in [directus/directus](https://github.com/directus/directus/discussions/new) * Email us at [security@directus.io](mailto:security@directus.io)
Are you affected?
Enter the version of the package you're using.