PT-2023-21157 · Directus · Directus

Erik Van Oosbree

+1

·

Publicado

2023-03-07

·

Atualizado

2023-03-14

·

CVE-2023-27481

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 9.16.0
Description The issue allows users with read access to the password field in directus users to extract argon2 password hashes by brute forcing the export functionality combined with a starts with filter. This enables the enumeration of password hashes. However, taking over accounts is unlikely with current hardware unless the hashes can be reversed.
Recommendations For versions prior to 9.16.0, upgrade to version 9.16.0 or later to patch the issue. As a temporary workaround for users unable to upgrade, ensure that no user has read access to the password field in directus users.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-27481
GHSA-M5Q3-8WGF-X8XF

Produtos afetados

Directus