directus is vulnerable to Improper Authorization
92
Critical Risk
When a Directus instance is configured for public WebSocket REST access, a failed authentication message on an already connected socket replaces the client's public accountability with a null accountability and leaves the connection open. Null accountability is the internal-trust state for which the service layer skips permission evaluation entirely, so every subsequent item message runs with no authorization check. An unauthenticated caller can deliberately submit an invalid token, or let a token expire, and then read, create, update, or delete records in any user-defined collection, including mass deletion by filter. The fix retains a public-role accountability object on authentication failure and token expiry in every WebSocket mode.
You are affected if you are using a version that falls within the vulnerable range and you have WebSockets enabled with the REST WebSocket authentication mode set to public.
directus is vulnerable to Improper Authorization in versions 0.0.1 - 12.0.2.
Upgrade the directus library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant