VDB
Sign up
MEDIUM6.5

GHSA-77qm-wvqq-fg79

Directus vulnerable to unhandled exception on illegal filename_disk value

Quick fix

GHSA-77qm-wvqq-fg79 — directus: upgrade to the fixed version with the command below.

npm install directus@9.15.0

Details

The Directus process can be aborted by having an authorized user update the `filename_disk` value to a folder and accessing that file through the `/assets` endpoint.

The vulnerability is patched and released in v9.15.0.

You can prevent this problem by making sure no (untrusted) non-admin users have permissions to update the `filename_disk` field on `directus_files`.

### For more information

If you have any questions or comments about this advisory: * Open a Discussion in [directus/directus](https://github.com/directus/directus/discussions) * Email us at [security@directus.io](mailto:security@directus.io)

### Credits

This vulnerability was first discovered and reported by Witold Gorecki.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 9.15.0
Fixnpm install directus@9.15.0

References