PT-2022-18147 · Directus · Directus
Rijk Van Zanten
·
Published
2022-04-05
·
Updated
2023-01-05
·
CVE-2022-26969
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 9.7.0
Description
The default settings of CORS ORIGIN and CORS ENABLED in Directus are true, which could lead to unauthorized access in uncontrolled environments when the configuration hasn't been changed. This is due to the default value for the
CORS ENABLED and CORS ORIGIN configuration being very permissive.Recommendations
For versions prior to 9.7.0, configure the CORS environment variables to match your project's usage, rather than leaving them at the permissive defaults.
Update to version 9.7.0 or later, where the default values for CORS have been changed to be less permissive.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directus