Intel

AIKIDO-2024-10507

directus is vulnerable to Authentication Bypass

Authentication Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 3, 2024

75

High Risk

This Affects:

JSdirectus
10.11.2 - 11.2.2
Fixed in 11.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow unauthenticated access to sensitive data through a public WebSocket in the API component. This vulnerability can enable attackers to intercept or manipulate data without authentication, posing risks to data confidentiality and integrity.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

directus is vulnerable to Authentication Bypass in versions 10.11.2 - 11.2.2.

How to fix this

Upgrade the directus library to the patch version.