VDB
Sign up
MEDIUM5.0

GHSA-5h75-pvq4-82c9

Server-Side Request Forgery in Directus

Quick fix

GHSA-5h75-pvq4-82c9 — directus: upgrade to the fixed version with the command below.

npm install directus@9.7.0

Details

Directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality, which allows a low privileged user to perform internal network port scans.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 9.0.0-beta.2Fixed in: 9.7.0
Fixnpm install directus@9.7.0

References