PT-2021-18378 · Apache · Apache Http Server

Moritz Friedmann

+1

·

Published

2021-04-07

·

Updated

2021-04-13

·

CVE-2021-29641

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Directus 8 versions prior to 8.8.2
Description The issue allows remote authenticated users to execute arbitrary code. This is possible because file-upload permissions include the ability to upload a .php file to the main upload directory and/or upload a .php file and a .htaccess file to a subdirectory. The exploitation is successful only for certain installations with the Apache HTTP Server and the local-storage driver.
Recommendations For Directus 8 versions prior to 8.8.2, update to version 8.8.2 or later to resolve the issue. As a temporary workaround, consider restricting file upload permissions to prevent the upload of .php and .htaccess files.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29641

Affected Products

Apache Http Server