GHSA-77qm-wvqq-fg79

    Dashboard / Vulnerabilities / GHSA-77qm-wvqq-fg79

    GHSA-77qm-wvqq-fg79

    Published: 30 Aug 2022Last Modified: 8 Nov 2023

    Summary: Directus vulnerable to unhandled exception on illegal filename_disk value

    Details: The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. The vulnerability is patched and released in v9.15.0. You can prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`. ### For more information If you have any questions or comments about this advisory: * Open a Discussion in [directus/directus](https://github.com/directus/directus/discussions) * Email us at [[email protected]](mailto:[email protected]) ### Credits This vulnerability was first discovered and reported by Witold Gorecki.

    Affected packages

    Package

    Name: directus

    Purl: pkg:npm/directus

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -9.15.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-77qm-wvqq-fg79 | CVE-DB