Information disclosure in Directus - CVE-2023-27481
Published: March 7, 2023 / Updated: April 23, 2026
Directus
Directus
Description
The vulnerability allows a remote user to disclose password hashes.
The vulnerability exists due to exposure of sensitive information in the export functionality for the directus_users password field when combining export queries with a _starts_with filter. A remote privileged user can brute force export queries to disclose password hashes.
The issue affects users who have read access to the password field in directus_users.