PT-2025-5336 · Directus · Directus

Viters

·

Published

2025-01-23

·

Updated

2025-11-18

·

CVE-2025-24353

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.2.0
Description The issue allows a typical user to specify an arbitrary role when sharing an item, enabling them to use a higher-privileged role to view fields they should not be able to see. This affects instances that use the share feature and have a specific roles hierarchy and fields not visible to certain roles.
Recommendations For versions prior to 11.2.0, update to version 11.2.0 or later, which contains a patch to resolve the issue. As a temporary workaround, consider restricting the use of the share feature to admins only, or limit the fields that can be shared to those visible to the sharing user.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-05409
CVE-2025-24353
GHSA-PMF4-V838-29HG

Affected Products

Directus