Monospace

Directus

44 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 14.05.2024 15:39:31
  • Zuletzt bearbeitet 03.01.2025 16:20:01

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and t...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 14.05.2024 15:39:31
  • Zuletzt bearbeitet 03.01.2025 16:19:08

Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, th...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 12.03.2024 21:15:59
  • Zuletzt bearbeitet 03.01.2025 16:17:32

Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's a redirect...

  • EPSS 0.09%
  • Veröffentlicht 12.03.2024 21:15:59
  • Zuletzt bearbeitet 03.01.2025 16:14:55

Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g...

  • EPSS 0.33%
  • Veröffentlicht 01.03.2024 16:15:46
  • Zuletzt bearbeitet 03.01.2025 16:14:03

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 01.03.2024 16:15:46
  • Zuletzt bearbeitet 03.01.2025 15:57:16

Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar emai...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 19.10.2023 19:15:15
  • Zuletzt bearbeitet 21.11.2024 08:27:25

Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could lever...

  • EPSS 0.11%
  • Veröffentlicht 25.07.2023 23:15:10
  • Zuletzt bearbeitet 21.11.2024 08:13:42

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. `user_created IS $CURRENT_USER`) are not properly checked when using GraphQL subscri...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 04.04.2023 15:15:07
  • Zuletzt bearbeitet 14.02.2025 19:15:12

An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 24.03.2023 00:15:15
  • Zuletzt bearbeitet 21.11.2024 07:55:05

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This i...