Логотип exploitDog
bind:CVE-2024-39896
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-39896

Количество 2

Количество 2

nvd логотип

CVE-2024-39896

больше 1 года назад

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an email address exists in Directus and belongs to a known SSO provider then it will throw a "helpful" error that the user belongs to another provider. This vulnerability is fixed in 10.13.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-jgf4-vwc3-r46v

больше 1 года назад

Directus Allows Single Sign-On User Enumeration

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-39896

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can be possible to enumerate existing SSO users in the instance. This is possible because if an email address exists in Directus and belongs to a known SSO provider then it will throw a "helpful" error that the user belongs to another provider. This vulnerability is fixed in 10.13.0.

CVSS3: 7.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-jgf4-vwc3-r46v

Directus Allows Single Sign-On User Enumeration

CVSS3: 7.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу