Monospace

Directus

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 08.10.2024 18:15:31
  • Zuletzt bearbeitet 14.04.2025 12:15:14

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed in system logs which may be persisted. The access token in `req.query` is not redacted when...

  • EPSS 0.24%
  • Veröffentlicht 18.09.2024 17:15:19
  • Zuletzt bearbeitet 17.11.2025 18:49:17

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2`...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 10.09.2024 19:15:22
  • Zuletzt bearbeitet 17.11.2025 18:42:18

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This h...

  • EPSS 0.06%
  • Veröffentlicht 15.08.2024 04:15:07
  • Zuletzt bearbeitet 19.05.2025 19:15:47

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not i...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 15.08.2024 03:15:04
  • Zuletzt bearbeitet 19.05.2025 18:15:26

Directus v10.13.0 allows an authenticated external attacker to execute arbitrary JavaScript on the client. This is possible because the application injects an attacker-controlled parameter that will be stored in the server and used by the client into...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 08.07.2024 18:15:08
  • Zuletzt bearbeitet 03.01.2025 16:30:43

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an...

Exploit
  • EPSS 0.86%
  • Veröffentlicht 08.07.2024 17:15:11
  • Zuletzt bearbeitet 03.01.2025 16:29:09

Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is a type of attack where an attacker exploits the flexibility of GraphQL to overwhelm a server by reque...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 08.07.2024 17:15:11
  • Zuletzt bearbeitet 04.09.2025 14:43:40

Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} w...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 08.07.2024 16:15:08
  • Zuletzt bearbeitet 21.11.2024 09:28:14

Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It was fixed by resolving all DNS names and checking if the requested IP is an internal IP address. Howe...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 03.06.2024 15:15:09
  • Zuletzt bearbeitet 03.01.2025 16:24:06

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string generation utility will create a memory issue breaking the capability to generate random stri...