CVE-2023-22894 Splunk · SPL

Detect Strapi Cleartext Storage of Sensitive Information (CVE-2023-22894) in Splunk

Detects exploitation and exposure conditions related to CVE-2023-22894, a cleartext storage of sensitive information vulnerability (CWE-312) in Strapi headless CMS. Affected Strapi deployments store sensitive information such as database connection strings, API tokens, and private metadata in a form that can be retrieved by unauthorized actors through the admin/content API, log files, or exposed configuration. This KEV-listed vulnerability is actively exploited; detection focuses on unauthorized access to Strapi configuration/content-type endpoints, anomalous retrieval of sensitive fields, and reads of plaintext secrets from Strapi filesystem/log artifacts.

MITRE ATT&CK

Tactic
Credential Access Discovery Collection

SPL Detection Query

Splunk (SPL)
spl
index=web OR index=proxy sourcetype IN ("ms:iis","nginx:access","apache:access") (uri_path="*/content-manager/*" OR uri_path="*/content-type-builder*" OR uri_path="*/admin/users*" OR uri_path="*/api/users*" OR uri_query="*password*" OR uri_query="*apiToken*" OR uri_query="*connectionString*" OR uri_query="*secret*")
| stats count AS hits values(uri_path) AS paths dc(uri_path) AS distinct_paths by src_ip, _time span=15m
| where hits > 5
| sort - hits
high severity medium confidence

Aggregates Strapi configuration/user API requests and sensitive-field query references per source IP to flag enumeration of cleartext secrets associated with CVE-2023-22894.

Data Sources

IIS/Web Server LogsReverse Proxy Access Logs

Required Sourcetypes

ms:iisnginx:accessapache:access

False Positives & Tuning

  • Strapi admins performing bulk content management operations
  • Load balancer health probes against /_health
  • Scheduled data export jobs reading user collections

Other platforms for CVE-2023-22894


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Enumerate Strapi content-manager collection types

    Expected signal: Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.

  2. Test 2Request Strapi user records referencing sensitive fields

    Expected signal: Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.

  3. Test 3Read cleartext secrets from Strapi config on host

    Expected signal: File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.


Response Playbook

Triage

  1. Confirm the targeted host runs Strapi and identify its version against the CVE-2023-22894 fixed releases listed in the Strapi security advisory.
  2. Review the flagged source IP's full request history to determine whether it accessed content-manager, content-type-builder, or /api/users endpoints and whether responses returned fields such as password, apiToken, or connectionString.
  3. Determine whether the requests were authenticated (valid admin/API token) or unauthenticated, and whether the source IP is a known administrator, scanner, or unknown external host.
  4. Inspect Strapi application logs and configuration files for cleartext storage of database credentials, API tokens, or reset tokens that may have been exposed.

Containment

  1. Block the offending source IP(s) at the WAF/reverse proxy and restrict access to Strapi admin and config endpoints to trusted management networks.
  2. Rotate all secrets that may have been exposed in cleartext — database connection strings, API tokens, JWT secrets, and admin reset tokens.
  3. Take the affected Strapi instance offline or into maintenance mode if active exfiltration of secrets is confirmed.

Evidence Collection

  1. Preserve web server, reverse proxy, and Strapi application logs covering the suspected access window, including full request URIs and response sizes.
  2. Capture the Strapi configuration directory, environment files, and database to document which secrets were stored in cleartext at time of compromise.

Escalation Criteria

  • !Escalate to incident response if responses confirm that cleartext secrets (credentials, tokens) were returned to an untrusted source IP.
  • !Escalate if exposed secrets show subsequent use — e.g., database logins or API token usage from anomalous locations following the access.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >Strapi application logs and reverse proxy access logs showing requests to content-manager/content-type-builder/api/users endpoints
  • >Strapi config files and environment/database artifacts containing cleartext credentials and API tokens

Tuning Guidance

Baseline the IP ranges and user agents used by legitimate Strapi administrators and automation, then exclude them. Lower the per-window request threshold in low-traffic environments and raise it where monitoring/health probes inflate counts. Prioritize alerts where responses return non-trivial body sizes on user or config endpoints from untrusted sources.


Hunting Queries

Finds source IPs with high-volume access to Strapi configuration and user endpoints, indicative of secret enumeration.

Hunting — KQL
kql
W3CIISLog | where csUriStem has_any ("content-manager","content-type-builder","api/users") | summarize count() by cIP, csUriStem | where count_ > 10
Hunting — SPL
spl
index=web (uri_path="*content-manager*" OR uri_path="*api/users*") | stats count by src_ip, uri_path | where count > 10

Atomic Red Team Tests

Test 1 Enumerate Strapi content-manager collection types
linux

Simulates an attacker enumerating Strapi collection types to locate user and secret-bearing content.

Command

bash
for p in /content-manager/collection-types /content-type-builder /api/users; do curl -s -o /dev/null -w "%{http_code} $p\n" http://127.0.0.1:1337$p; done

Cleanup

bash
echo 'no cleanup required - read-only requests'

Expected Telemetry

Reverse proxy / web server access logs show repeated requests from one source to content-manager, content-type-builder, and api/users paths.

Expected Detection

KQL/SPL rules flag >5 Strapi config/user endpoint requests from a single source within the correlation window.

Test 2 Request Strapi user records referencing sensitive fields
linux

Requests Strapi user API with query parameters referencing sensitive field names to emulate secret harvesting.

Command

bash
curl -s 'http://127.0.0.1:1337/api/users?fields[0]=password&fields[1]=resetPasswordToken&fields[2]=apiToken' -o /tmp/strapi_users.json

Cleanup

bash
rm -f /tmp/strapi_users.json

Expected Telemetry

Web logs contain URIs with password/resetPasswordToken/apiToken query parameters against the Strapi users endpoint.

Expected Detection

Sensitive-field match branch of the detection fires on the query string referencing password/apiToken.

Test 3 Read cleartext secrets from Strapi config on host
windows

Reads a Strapi environment/config file to emulate local retrieval of cleartext-stored secrets.

Command

powershell
powershell -c "Get-Content 'C:\\strapi\\.env','C:\\strapi\\config\\database.js' | Select-String -Pattern 'DATABASE_PASSWORD|API_TOKEN_SALT|JWT_SECRET|connectionString'"

Cleanup

powershell
echo done

Expected Telemetry

File read / process-command-line telemetry shows access to Strapi .env and database config files and grepping for secret keywords.

Expected Detection

EDR file-access and command-line monitoring flags access to Strapi secret config files containing cleartext credentials.

Related Detections