PT-2022-23129 · Directus · Directus
Witold Gorecki
·
Published
2022-08-19
·
Updated
2022-08-30
·
CVE-2022-36031
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 9.15.0
Description
The Directus process can be aborted by having an authorized user update the
filename disk value to a folder and accessing that file through the "/assets" endpoint. This issue has been patched and release v9.15.0 contains the fix. Users are advised to upgrade to prevent the problem.Recommendations
For versions prior to 9.15.0, upgrade to version 9.15.0 or later to resolve the issue.
As a temporary workaround for users unable to upgrade, prevent the problem by making sure no (untrusted) non-admin users have permissions to update the
filename disk field on directus files.Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directus