CVE-2023-22894

Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894)

Credential Access Discovery Collection Last updated:

Detects exploitation and exposure conditions related to CVE-2023-22894, a cleartext storage of sensitive information vulnerability (CWE-312) in Strapi headless CMS. Affected Strapi deployments store sensitive information such as database connection strings, API tokens, and private metadata in a form that can be retrieved by unauthorized actors through the admin/content API, log files, or exposed configuration. This KEV-listed vulnerability is actively exploited; detection focuses on unauthorized access to Strapi configuration/content-type endpoints, anomalous retrieval of sensitive fields, and reads of plaintext secrets from Strapi filesystem/log artifacts.

Vulnerability Intelligence

KEV — Known Exploited

What is CVE-2023-22894 Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894)?

Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894) (CVE-2023-22894) maps to the Credential Access and Discovery and Collection tactics — the adversary is trying to steal account names and passwords in MITRE ATT&CK.

This page provides production-ready detection logic for Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894), covering the data sources and telemetry it touches: IIS/Web Server Logs, WAF / Proxy Logs. The queries below are rated high severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Credential Access Discovery Collection
Microsoft Sentinel / Defender
kusto
let strapiSensitivePaths = dynamic(["/content-manager/collection-types", "/content-type-builder", "/admin/users", "/api/users", "/_health", "/admin/content-manager"]);
let sensitiveFields = dynamic(["password", "resetPasswordToken", "apiToken", "accessKey", "secret", "connectionString", "database"]);
union isfuzzy=true W3CIISLog, CommonSecurityLog
| where TimeGenerated > ago(1d)
| extend reqUri = tolower(coalesce(column_ifexists("csUriStem", ""), column_ifexists("RequestURL", "")))
| extend srcIp = coalesce(column_ifexists("cIP", ""), column_ifexists("SourceIP", ""))
| where reqUri has_any (strapiSensitivePaths) or reqUri has_any (sensitiveFields)
| summarize RequestCount = count(), Paths = make_set(reqUri, 50) by srcIp, bin(TimeGenerated, 15m)
| where RequestCount > 5
| project TimeGenerated, srcIp, RequestCount, Paths

Identifies bursts of requests from a single source to Strapi configuration, content-manager, and user API endpoints, or requests referencing sensitive field names, consistent with harvesting cleartext secrets exposed by CVE-2023-22894.

high severity medium confidence

Data Sources

IIS/Web Server Logs WAF / Proxy Logs

Required Tables

W3CIISLog CommonSecurityLog

False Positives

  • Legitimate Strapi administrators browsing the content-manager and content-type-builder during normal CMS operations
  • Automated monitoring or uptime checks hitting the /_health endpoint frequently
  • Backup or migration tooling enumerating collection-types and user records on schedule

Sigma rule & cross-platform mapping

The detection logic for Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894) (CVE-2023-22894) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: network_connection
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Enumerate Strapi content-manager collection types

    Expected signal: Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.

  2. Test 2Request Strapi user records referencing sensitive fields

    Expected signal: Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.

  3. Test 3Read cleartext secrets from Strapi config on host

    Expected signal: File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.


Response Playbook

Triage

  1. Confirm the targeted host runs Strapi and identify its version against the CVE-2023-22894 fixed releases listed in the Strapi security advisory.
  2. Review the flagged source IP's full request history to determine whether it accessed content-manager, content-type-builder, or /api/users endpoints and whether responses returned fields such as password, apiToken, or connectionString.
  3. Determine whether the requests were authenticated (valid admin/API token) or unauthenticated, and whether the source IP is a known administrator, scanner, or unknown external host.
  4. Inspect Strapi application logs and configuration files for cleartext storage of database credentials, API tokens, or reset tokens that may have been exposed.

Containment

  1. Block the offending source IP(s) at the WAF/reverse proxy and restrict access to Strapi admin and config endpoints to trusted management networks.
  2. Rotate all secrets that may have been exposed in cleartext — database connection strings, API tokens, JWT secrets, and admin reset tokens.
  3. Take the affected Strapi instance offline or into maintenance mode if active exfiltration of secrets is confirmed.

Evidence Collection

  1. Preserve web server, reverse proxy, and Strapi application logs covering the suspected access window, including full request URIs and response sizes.
  2. Capture the Strapi configuration directory, environment files, and database to document which secrets were stored in cleartext at time of compromise.

Escalation Criteria

  • ! Escalate to incident response if responses confirm that cleartext secrets (credentials, tokens) were returned to an untrusted source IP.
  • ! Escalate if exposed secrets show subsequent use — e.g., database logins or API token usage from anomalous locations following the access.

Investigation Guide

Forensic Artifacts

  • > Strapi application logs and reverse proxy access logs showing requests to content-manager/content-type-builder/api/users endpoints
  • > Strapi config files and environment/database artifacts containing cleartext credentials and API tokens

Tuning Guidance

Baseline the IP ranges and user agents used by legitimate Strapi administrators and automation, then exclude them. Lower the per-window request threshold in low-traffic environments and raise it where monitoring/health probes inflate counts. Prioritize alerts where responses return non-trivial body sizes on user or config endpoints from untrusted sources.


Hunting Queries

Finds source IPs with high-volume access to Strapi configuration and user endpoints, indicative of secret enumeration.

Hunting — KQL
kql
W3CIISLog | where csUriStem has_any ("content-manager","content-type-builder","api/users") | summarize count() by cIP, csUriStem | where count_ > 10
Hunting — SPL
spl
index=web (uri_path="*content-manager*" OR uri_path="*api/users*") | stats count by src_ip, uri_path | where count > 10

Atomic Red Team Tests

Test 1 Enumerate Strapi content-manager collection types
linux

Simulates an attacker enumerating Strapi collection types to locate user and secret-bearing content.

Command

bash
for p in /content-manager/collection-types /content-type-builder /api/users; do curl -s -o /dev/null -w "%{http_code} $p\n" http://127.0.0.1:1337$p; done

Cleanup

bash
echo 'no cleanup required - read-only requests'

Expected Telemetry

Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.

Expected Detection

KQL/SPL rules flag >5 Strapi config/user endpoint requests from a single source within the correlation window.

Test 2 Request Strapi user records referencing sensitive fields
linux

Requests Strapi user API with query parameters referencing sensitive field names to emulate secret harvesting.

Command

bash
curl -s 'http://127.0.0.1:1337/api/users?fields[0]=password&fields[1]=resetPasswordToken&fields[2]=apiToken' -o /tmp/strapi_users.json

Cleanup

bash
rm -f /tmp/strapi_users.json

Expected Telemetry

Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.

Expected Detection

Sensitive-field match branch of the detection fires on the query string referencing password/apiToken.

Test 3 Read cleartext secrets from Strapi config on host
windows

Reads a Strapi environment/config file to emulate local retrieval of cleartext-stored secrets.

Command

powershell
powershell -c "Get-Content 'C:\\strapi\\.env','C:\\strapi\\config\\database.js' | Select-String -Pattern 'DATABASE_PASSWORD|API_TOKEN_SALT|JWT_SECRET|connectionString'"

Cleanup

powershell
echo done

Expected Telemetry

File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.

Expected Detection

EDR file-access and command-line monitoring flags access to Strapi secret config files containing cleartext credentials.

Related Detections