- EPSS 0.44%
- Veröffentlicht 08.07.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 09:28:14
Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It was fixed by resolving all DNS names and checking if the requested IP is an internal IP address. Howe...
CVE-2024-36128
- EPSS 0.62%
- Veröffentlicht 03.06.2024 15:15:09
- Zuletzt bearbeitet 03.01.2025 16:24:06
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string generation utility will create a memory issue breaking the capability to generate random stri...
CVE-2024-34709
- EPSS 0.45%
- Veröffentlicht 14.05.2024 15:39:31
- Zuletzt bearbeitet 03.01.2025 16:20:01
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and t...
CVE-2024-34708
- EPSS 0.76%
- Veröffentlicht 14.05.2024 15:39:31
- Zuletzt bearbeitet 03.01.2025 16:19:08
Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, th...
CVE-2024-28239
- EPSS 0.58%
- Veröffentlicht 12.03.2024 21:15:59
- Zuletzt bearbeitet 03.01.2025 16:17:32
Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's a redirect...
CVE-2024-28238
- EPSS 0.25%
- Veröffentlicht 12.03.2024 21:15:59
- Zuletzt bearbeitet 03.01.2025 16:14:55
Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is passed via GET request. Inclusion of session tokens in URLs poses a security risk as URLs are often logged in various places (e.g...
CVE-2024-27296
- EPSS 0.57%
- Veröffentlicht 01.03.2024 16:15:46
- Zuletzt bearbeitet 03.01.2025 16:14:03
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a ...
CVE-2024-27295
- EPSS 0.7%
- Veröffentlicht 01.03.2024 16:15:46
- Zuletzt bearbeitet 03.01.2025 15:57:16
Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive a password reset email of a victim user, specifically having it arrive at a similar emai...
CVE-2023-45820
- EPSS 0.69%
- Veröffentlicht 19.10.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 08:27:25
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could lever...
CVE-2023-38503
- EPSS 0.5%
- Veröffentlicht 25.07.2023 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:13:42
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. `user_created IS $CURRENT_USER`) are not properly checked when using GraphQL subscri...