GHSA-g27j-74fp-xfpr
Insecure default value for CORS configuration
Quick fix
GHSA-g27j-74fp-xfpr — directus: upgrade to the fixed version with the command below.
npm install directus@9.7.0Details
### Impact
The default value for the `CORS_ENABLED` and `CORS_ORIGIN` configuration was set to be very permissive by default. This could lead to unauthorized access in uncontrolled environments when the configuration hasn't been changed.
### Patches
The default values for CORS have been changed in https://github.com/directus/directus/pull/12022 which is released under 9.7.0
### Workarounds
Configure the CORS environment variables to match your project's usage, rather than leaving them at the (permissive) defaults.
### For more information If you have any questions or comments about this advisory: * Open an issue in [directus/directus](https://github.com/directus/directus) * Email us at [security@directus.io](mailto:security@directus.io)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/directus/directus/security/advisories/GHSA-g27j-74fp-xfpr[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-26969[ADVISORY]
- https://github.com/directus/directus/pull/12022[WEB]
- https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS[WEB]
- https://github.com/directus/directus[PACKAGE]
- https://github.com/directus/directus/blob/8daed9c41baeaf1d08c1e292bf9f0dcef65e48fb/docs/configuration/config-options.md[WEB]
- https://github.com/directus/directus/releases/tag/v9.7.0[WEB]
- https://security.snyk.io/vuln/SNYK-JS-DIRECTUS-2441822[WEB]