PT-2024-21802 · Directus · Directus

Rijkvanzanten

·

Published

2024-03-01

·

Updated

2025-01-03

·

CVE-2024-27296

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 10.8.3
Description Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information, a malicious attacker can look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version.
Recommendations For versions prior to 10.8.3, update to version 10.8.3 or newer to resolve the issue. As a temporary workaround, consider restricting access to the compiled JS bundles to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-27296
GHSA-5MHG-WV8W-P59J

Affected Products

Directus