CVE-2024-39701
Directus Incorrectly handles _in` filter
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays as valid so expressions like {"role": {"_in": $CURRENT_USER.some_field}} would evaluate to true allowing the request to pass. This results in Broken Access Control because the rule fails to do what it was intended to do: Pass rule if **field** matches any of the **values**. This vulnerability is fixed in 10.6.0.
Directus es una API y un panel de aplicaciones en tiempo real para administrar el contenido de la base de datos SQL. Directus >=9.23.0, <=v10.5.3 maneja incorrectamente los operadores _in, _nin. Evalúa matrices vacías como válidas, por lo que expresiones como {"role": {"_in": $CURRENT_USER.some_field}} se evaluarían como verdaderas, lo que permitiría que se aprobara la solicitud. Esto da como resultado un control de acceso roto porque la regla no logra hacer lo que estaba previsto: aprobar la regla si el **field** coincide con alguno de los **values**. Esta vulnerabilidad se solucionó en 10.6.0.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-06-27 CVE Reserved
- 2024-07-08 CVE Published
- 2024-07-09 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/directus/directus/security/advisories/GHSA-hxgm-ghmv-xjjm | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Directus Search vendor "Directus" | Directus Search vendor "Directus" for product "Directus" | >= 9.23.0 < 10.6.0 Search vendor "Directus" for product "Directus" and version " >= 9.23.0 < 10.6.0" | en |
Affected
|