PT-2022-18147 · Directus · Directus

Rijk Van Zanten

·

Published

2022-04-05

·

Updated

2023-01-05

·

CVE-2022-26969

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Directus versions prior to 9.7.0
Description The default settings of CORS ORIGIN and CORS ENABLED in Directus are true, which could lead to unauthorized access in uncontrolled environments when the configuration hasn't been changed. This is due to the default value for the CORS ENABLED and CORS ORIGIN configuration being very permissive.
Recommendations For versions prior to 9.7.0, configure the CORS environment variables to match your project's usage, rather than leaving them at the permissive defaults. Update to version 9.7.0 or later, where the default values for CORS have been changed to be less permissive.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-26969
GHSA-G27J-74FP-XFPR

Affected Products

Directus