Detect Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894) in IBM QRadar
Detects exploitation and exposure conditions related to CVE-2023-22894, a cleartext storage of sensitive information vulnerability (CWE-312) in Strapi headless CMS. Affected Strapi deployments store sensitive information such as database connection strings, API tokens, and private metadata in a form that can be retrieved by unauthorized actors through the admin/content API, log files, or exposed configuration. This KEV-listed vulnerability is actively exploited; detection focuses on unauthorized access to Strapi configuration/content-type endpoints, anomalous retrieval of sensitive fields, and reads of plaintext secrets from Strapi filesystem/log artifacts.
MITRE ATT&CK
- Tactic
- Credential Access Discovery Collection
QRadar Detection Query
SELECT sourceip, COUNT(*) AS hits, UniqueCount("URL") AS distinct_urls FROM events WHERE LOGSOURCETYPENAME(devicetype) IN ('Apache HTTP Server','Microsoft IIS','Nginx') AND ("URL" ILIKE '%/content-manager/%' OR "URL" ILIKE '%/content-type-builder%' OR "URL" ILIKE '%/api/users%' OR "URL" ILIKE '%password%' OR "URL" ILIKE '%apiToken%' OR "URL" ILIKE '%connectionString%') GROUP BY sourceip HAVING hits > 5 LAST 1 HOURS Flags source IPs issuing elevated volumes of Strapi config/user endpoint and sensitive-field requests, a signature of exploitation of the cleartext storage flaw CVE-2023-22894.
Data Sources
Required Tables
False Positives & Tuning
- Trusted admin workstations managing Strapi content
- Monitoring systems polling API endpoints
- Content synchronization jobs reading user data
Other platforms for CVE-2023-22894
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Enumerate Strapi content-manager collection types
Expected signal: Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.
- Test 2Request Strapi user records referencing sensitive fields
Expected signal: Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.
- Test 3Read cleartext secrets from Strapi config on host
Expected signal: File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.
References (5)
- https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve
- https://github.com/strapi/strapi/releases
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2023-22894
Response Playbook
Triage
- Confirm the targeted host runs Strapi and identify its version against the CVE-2023-22894 fixed releases listed in the Strapi security advisory.
- Review the flagged source IP's full request history to determine whether it accessed content-manager, content-type-builder, or /api/users endpoints and whether responses returned fields such as password, apiToken, or connectionString.
- Determine whether the requests were authenticated (valid admin/API token) or unauthenticated, and whether the source IP is a known administrator, scanner, or unknown external host.
- Inspect Strapi application logs and configuration files for cleartext storage of database credentials, API tokens, or reset tokens that may have been exposed.
Containment
- Block the offending source IP(s) at the WAF/reverse proxy and restrict access to Strapi admin and config endpoints to trusted management networks.
- Rotate all secrets that may have been exposed in cleartext — database connection strings, API tokens, JWT secrets, and admin reset tokens.
- Take the affected Strapi instance offline or into maintenance mode if active exfiltration of secrets is confirmed.
Evidence Collection
- Preserve web server, reverse proxy, and Strapi application logs covering the suspected access window, including full request URIs and response sizes.
- Capture the Strapi configuration directory, environment files, and database to document which secrets were stored in cleartext at time of compromise.
Escalation Criteria
- !Escalate to incident response if responses confirm that cleartext secrets (credentials, tokens) were returned to an untrusted source IP.
- !Escalate if exposed secrets show subsequent use — e.g., database logins or API token usage from anomalous locations following the access.
Investigation Guide
Related Techniques
Forensic Artifacts
- >
Strapi application logs and reverse proxy access logs showing requests to content-manager/content-type-builder/api/users endpoints - >
Strapi config files and environment/database artifacts containing cleartext credentials and API tokens
Tuning Guidance
Baseline the IP ranges and user agents used by legitimate Strapi administrators and automation, then exclude them. Lower the per-window request threshold in low-traffic environments and raise it where monitoring/health probes inflate counts. Prioritize alerts where responses return non-trivial body sizes on user or config endpoints from untrusted sources.
Hunting Queries
Finds source IPs with high-volume access to Strapi configuration and user endpoints, indicative of secret enumeration.
W3CIISLog | where csUriStem has_any ("content-manager","content-type-builder","api/users") | summarize count() by cIP, csUriStem | where count_ > 10 index=web (uri_path="*content-manager*" OR uri_path="*api/users*") | stats count by src_ip, uri_path | where count > 10 Atomic Red Team Tests
Simulates an attacker enumerating Strapi collection types to locate user and secret-bearing content.
Command
for p in /content-manager/collection-types /content-type-builder /api/users; do curl -s -o /dev/null -w "%{http_code} $p\n" http://127.0.0.1:1337$p; done Cleanup
echo 'no cleanup required - read-only requests' Expected Telemetry
Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.
Expected Detection
KQL/SPL rules flag >5 Strapi config/user endpoint requests from a single source within the correlation window.
Requests Strapi user API with query parameters referencing sensitive field names to emulate secret harvesting.
Command
curl -s 'http://127.0.0.1:1337/api/users?fields[0]=password&fields[1]=resetPasswordToken&fields[2]=apiToken' -o /tmp/strapi_users.json Cleanup
rm -f /tmp/strapi_users.json Expected Telemetry
Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.
Expected Detection
Sensitive-field match branch of the detection fires on the query string referencing password/apiToken.
Reads a Strapi environment/config file to emulate local retrieval of cleartext-stored secrets.
Command
powershell -c "Get-Content 'C:\\strapi\\.env','C:\\strapi\\config\\database.js' | Select-String -Pattern 'DATABASE_PASSWORD|API_TOKEN_SALT|JWT_SECRET|connectionString'" Cleanup
echo done Expected Telemetry
File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.
Expected Detection
EDR file-access and command-line monitoring flags access to Strapi secret config files containing cleartext credentials.