Executive brief
Directus is a headless CMS that manages content and user authentication for web applications. When configured with both single sign-on (SSO) providers and local username/password authentication, an attacker can enumerate which email addresses are registered as SSO users by observing different error messages during login attempts. This information disclosure could aid in targeted social engineering or account takeover attacks.
Technical details
The vulnerability is a user enumeration flaw (CWE-200) in Directus authentication logic. When a user attempts to log in locally with an email address that exists in Directus but is associated with an SSO provider, the system returns a specific error message stating the account belongs to another provider. For non-existent email addresses, a generic error is returned. An unauthenticated attacker can exploit this by submitting login attempts via the web form or API (no credentials required) and comparing error responses to determine which email addresses are registered SSO users. The vulnerability affects versions 9.11 through 10.12.x. A patch is available in version 10.13.0. As a workaround, administrators can disable local authentication with the AUTH_DISABLE_DEFAULT="true" environment variable.
Affected products
- Directus Directus 9.11 through 10.12.x
Timeline
- 2024-07-08: disclosed: Vulnerability disclosed in GitHub Advisory GHSA-jgf4-vwc3-r46v
- 2024-07-08: patched: Patch released in Directus version 10.13.0
References
- https://api.github.com/users/rosmelortizpimentel
- https://github.com/rosmelortizpimentel
- https://api.github.com/users/rosmelortizpimentel/gists%7B/gist_id%7D
- https://api.github.com/users/rosmelortizpimentel/repos
- https://avatars.githubusercontent.com/u/91397032?v=4
- https://api.github.com/users/rosmelortizpimentel/events%7B/privacy%7D