Directus vulnerable to unhandled exception on illegal filename_disk value
GHSA-77qm-wvqq-fg79 · CVE-2022-36031
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
The Directus process can be aborted by having an authorized user update the filename_disk value to a folder and accessing that file through the /assets endpoint.
The vulnerability is patched and released in v9.15.0.
You can prevent this problem by making sure no (untrusted) non-admin users have permissions to update the filename_disk field on directus_files.
For more information
If you have any questions or comments about this advisory:
- Open a Discussion in directus/directus
- Email us at security@directus.io
Credits
This vulnerability was first discovered and reported by Witold Gorecki.
Ready to move
Start Securing
Free, no credit card | First findings in minutes