Логотип exploitDog
bind:CVE-2022-36031
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-36031

Количество 2

Количество 2

nvd логотип

CVE-2022-36031

больше 3 лет назад

Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. This vulnerability has been patched and release v9.15.0 contains the fix. Users are advised to upgrade. Users unable to upgrade may prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-77qm-wvqq-fg79

больше 3 лет назад

Directus vulnerable to unhandled exception on illegal filename_disk value

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-36031

Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint. This vulnerability has been patched and release v9.15.0 contains the fix. Users are advised to upgrade. Users unable to upgrade may prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-77qm-wvqq-fg79

Directus vulnerable to unhandled exception on illegal filename_disk value

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу