Vulnerabilities
Vulnerable Software
Monospace:  >> Directus  >> 9.23.0  Security Vulnerabilities
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a malicious attacker can trivially look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. The problem has been resolved in versions 10.8.3 and newer.
CVSS Score
5.3
EPSS Score
0.004
Published
2024-03-01
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.
CVSS Score
4.2
EPSS Score
0.001
Published
2023-03-24


Contact Us

Shodan ® - All rights reserved