Monospace

Directus

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.08%
  • Veröffentlicht 04.04.2023 15:15:07
  • Zuletzt bearbeitet 14.02.2025 19:15:12

An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.

Exploit
  • EPSS 0.31%
  • Veröffentlicht 24.03.2023 00:15:15
  • Zuletzt bearbeitet 21.11.2024 07:55:05

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This i...

  • EPSS 0.6%
  • Veröffentlicht 07.03.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:59

Directus is a real-time API and App dashboard for managing SQL database content. In versions prior to 9.16.0 users with read access to the `password` field in `directus_users` can extract the argon2 password hashes by brute forcing the export functio...

Exploit
  • EPSS 0.96%
  • Veröffentlicht 03.03.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:51:37

Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when importing a file from a remote web server (POST to `/files/import`). An attacker can bypass the securit...

  • EPSS 0.93%
  • Veröffentlicht 26.12.2022 06:15:10
  • Zuletzt bearbeitet 14.04.2025 15:15:17

In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.

Exploit
  • EPSS 0.93%
  • Veröffentlicht 19.08.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:13

Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. Th...