CVE-2022-23080

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
22/06/2022
Last modified:
07/11/2023

Description

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rangerstudio:directus:*:*:*:*:*:*:*:* 9.0.1 (including) 9.6.0 (including)
cpe:2.3:a:rangerstudio:directus:9.0.0:beta10:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta11:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta12:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta13:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta14:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta4:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta5:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta7:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta8:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:beta9:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:rc0:*:*:*:*:*:*
cpe:2.3:a:rangerstudio:directus:9.0.0:rc1:*:*:*:*:*:*