VDB
Sign up
MEDIUM5.0

GHSA-68g8-c275-xf2m

Directus vulnerable to SSRF Loopback IP filter bypass

Quick fix

GHSA-68g8-c275-xf2m — directus: upgrade to the fixed version with the command below.

npm install directus@10.13.3

Details

### Impact If you're relying on blocking access to localhost using the default `0.0.0.0` filter this can be bypassed using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`)

### Workaround You can block this bypass by manually adding the `127.0.0.0/8` CIDR range which will block access to any `127.X.X.X` ip instead of just `127.0.0.1`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 10.13.3
Fixnpm install directus@10.13.3
npm/directus
Introduced in: 11.0.0Fixed in: 11.1.0
Fixnpm install directus@11.1.0
npm/@directus/api
Introduced in: 0Fixed in: 21.0.0
Fixnpm install @directus/api@21.0.0
npm/@directus/api
Introduced in: 22.0.0Fixed in: 22.1.1
Fixnpm install @directus/api@22.1.1

References