Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-36031

Опубликовано: 19 авг. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the filename_disk value to a folder and accessing that file through the /assets endpoint. This vulnerability has been patched and release v9.15.0 contains the fix. Users are advised to upgrade. Users unable to upgrade may prevent this problem by making sure no (untrusted) non-admin users have permissions to update the filename_disk field on directus_files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:monospace:directus:*:*:*:*:*:*:*:*
Версия до 9.15.0 (исключая)

EPSS

Процентиль: 48%
0.00246
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Directus vulnerable to unhandled exception on illegal filename_disk value

EPSS

Процентиль: 48%
0.00246
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-755