VDB
Sign up
MEDIUM6.5

GHSA-m5q3-8wgf-x8xf

Directus vulnerable to extraction of password hashes through export querying

Quick fix

GHSA-m5q3-8wgf-x8xf — directus: upgrade to the fixed version with the command below.

npm install directus@9.16.0

Details

### Impact

Users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by brute forcing the export functionality combined with a `_starts_with` filter. This allows the user to enumerate the password hashes.

### Patches

The problem has been patched by preventing any hashed/concealed field to be filtered against with the `_starts_with` or other string operator.

### Workarounds

Ensuring that no user has `read` access to the `password` field in `directus_users` is sufficient to prevent this vulnerability.

### For more information If you have any questions or comments about this advisory: * Open a Discussion in [directus/directus](https://github.com/directus/directus/discussions/new) * Email us at [security@directus.io](mailto:security@directus.io)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 9.16.0
Fixnpm install directus@9.16.0

References