5

CVE-2022-23080

Exploit
In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RangerstudioDirectus Version >= 9.0.1 <= 9.6.0
RangerstudioDirectus Version9.0.0 Updatebeta10
RangerstudioDirectus Version9.0.0 Updatebeta11
RangerstudioDirectus Version9.0.0 Updatebeta12
RangerstudioDirectus Version9.0.0 Updatebeta13
RangerstudioDirectus Version9.0.0 Updatebeta14
RangerstudioDirectus Version9.0.0 Updatebeta2
RangerstudioDirectus Version9.0.0 Updatebeta3
RangerstudioDirectus Version9.0.0 Updatebeta4
RangerstudioDirectus Version9.0.0 Updatebeta5
RangerstudioDirectus Version9.0.0 Updatebeta7
RangerstudioDirectus Version9.0.0 Updatebeta8
RangerstudioDirectus Version9.0.0 Updatebeta9
RangerstudioDirectus Version9.0.0 Updaterc0
RangerstudioDirectus Version9.0.0 Updaterc1
RangerstudioDirectus Version9.0.0 Updaterc10
RangerstudioDirectus Version9.0.0 Updaterc100
RangerstudioDirectus Version9.0.0 Updaterc101
RangerstudioDirectus Version9.0.0 Updaterc11
RangerstudioDirectus Version9.0.0 Updaterc12
RangerstudioDirectus Version9.0.0 Updaterc13
RangerstudioDirectus Version9.0.0 Updaterc14
RangerstudioDirectus Version9.0.0 Updaterc15
RangerstudioDirectus Version9.0.0 Updaterc17
RangerstudioDirectus Version9.0.0 Updaterc18
RangerstudioDirectus Version9.0.0 Updaterc19
RangerstudioDirectus Version9.0.0 Updaterc2
RangerstudioDirectus Version9.0.0 Updaterc20
RangerstudioDirectus Version9.0.0 Updaterc21
RangerstudioDirectus Version9.0.0 Updaterc22
RangerstudioDirectus Version9.0.0 Updaterc23
RangerstudioDirectus Version9.0.0 Updaterc24
RangerstudioDirectus Version9.0.0 Updaterc25
RangerstudioDirectus Version9.0.0 Updaterc26
RangerstudioDirectus Version9.0.0 Updaterc27
RangerstudioDirectus Version9.0.0 Updaterc28
RangerstudioDirectus Version9.0.0 Updaterc29
RangerstudioDirectus Version9.0.0 Updaterc3
RangerstudioDirectus Version9.0.0 Updaterc30
RangerstudioDirectus Version9.0.0 Updaterc31
RangerstudioDirectus Version9.0.0 Updaterc32
RangerstudioDirectus Version9.0.0 Updaterc33
RangerstudioDirectus Version9.0.0 Updaterc34
RangerstudioDirectus Version9.0.0 Updaterc35
RangerstudioDirectus Version9.0.0 Updaterc36
RangerstudioDirectus Version9.0.0 Updaterc37
RangerstudioDirectus Version9.0.0 Updaterc38
RangerstudioDirectus Version9.0.0 Updaterc39
RangerstudioDirectus Version9.0.0 Updaterc4
RangerstudioDirectus Version9.0.0 Updaterc40
RangerstudioDirectus Version9.0.0 Updaterc41
RangerstudioDirectus Version9.0.0 Updaterc42
RangerstudioDirectus Version9.0.0 Updaterc43
RangerstudioDirectus Version9.0.0 Updaterc44
RangerstudioDirectus Version9.0.0 Updaterc45
RangerstudioDirectus Version9.0.0 Updaterc46
RangerstudioDirectus Version9.0.0 Updaterc47
RangerstudioDirectus Version9.0.0 Updaterc48
RangerstudioDirectus Version9.0.0 Updaterc49
RangerstudioDirectus Version9.0.0 Updaterc5
RangerstudioDirectus Version9.0.0 Updaterc50
RangerstudioDirectus Version9.0.0 Updaterc51
RangerstudioDirectus Version9.0.0 Updaterc52
RangerstudioDirectus Version9.0.0 Updaterc53
RangerstudioDirectus Version9.0.0 Updaterc54
RangerstudioDirectus Version9.0.0 Updaterc55
RangerstudioDirectus Version9.0.0 Updaterc56
RangerstudioDirectus Version9.0.0 Updaterc57
RangerstudioDirectus Version9.0.0 Updaterc58
RangerstudioDirectus Version9.0.0 Updaterc59
RangerstudioDirectus Version9.0.0 Updaterc6
RangerstudioDirectus Version9.0.0 Updaterc60
RangerstudioDirectus Version9.0.0 Updaterc61
RangerstudioDirectus Version9.0.0 Updaterc62
RangerstudioDirectus Version9.0.0 Updaterc63
RangerstudioDirectus Version9.0.0 Updaterc64
RangerstudioDirectus Version9.0.0 Updaterc65
RangerstudioDirectus Version9.0.0 Updaterc66
RangerstudioDirectus Version9.0.0 Updaterc67
RangerstudioDirectus Version9.0.0 Updaterc68
RangerstudioDirectus Version9.0.0 Updaterc69
RangerstudioDirectus Version9.0.0 Updaterc7
RangerstudioDirectus Version9.0.0 Updaterc70
RangerstudioDirectus Version9.0.0 Updaterc71
RangerstudioDirectus Version9.0.0 Updaterc72
RangerstudioDirectus Version9.0.0 Updaterc73
RangerstudioDirectus Version9.0.0 Updaterc74
RangerstudioDirectus Version9.0.0 Updaterc75
RangerstudioDirectus Version9.0.0 Updaterc76
RangerstudioDirectus Version9.0.0 Updaterc77
RangerstudioDirectus Version9.0.0 Updaterc78
RangerstudioDirectus Version9.0.0 Updaterc79
RangerstudioDirectus Version9.0.0 Updaterc8
RangerstudioDirectus Version9.0.0 Updaterc80
RangerstudioDirectus Version9.0.0 Updaterc81
RangerstudioDirectus Version9.0.0 Updaterc82
RangerstudioDirectus Version9.0.0 Updaterc83
RangerstudioDirectus Version9.0.0 Updaterc84
RangerstudioDirectus Version9.0.0 Updaterc85
RangerstudioDirectus Version9.0.0 Updaterc86
RangerstudioDirectus Version9.0.0 Updaterc87
RangerstudioDirectus Version9.0.0 Updaterc88
RangerstudioDirectus Version9.0.0 Updaterc89
RangerstudioDirectus Version9.0.0 Updaterc9
RangerstudioDirectus Version9.0.0 Updaterc90
RangerstudioDirectus Version9.0.0 Updaterc91
RangerstudioDirectus Version9.0.0 Updaterc92
RangerstudioDirectus Version9.0.0 Updaterc93
RangerstudioDirectus Version9.0.0 Updaterc94
RangerstudioDirectus Version9.0.0 Updaterc95
RangerstudioDirectus Version9.0.0 Updaterc96
RangerstudioDirectus Version9.0.0 Updaterc97
RangerstudioDirectus Version9.0.0 Updaterc98
RangerstudioDirectus Version9.0.0 Updaterc99
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.259
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.