VDB
Sign up
CRITICAL9.8

GHSA-g27j-74fp-xfpr

Insecure default value for CORS configuration

Quick fix

GHSA-g27j-74fp-xfpr — directus: upgrade to the fixed version with the command below.

npm install directus@9.7.0

Details

### Impact

The default value for the `CORS_ENABLED` and `CORS_ORIGIN` configuration was set to be very permissive by default. This could lead to unauthorized access in uncontrolled environments when the configuration hasn't been changed.

### Patches

The default values for CORS have been changed in https://github.com/directus/directus/pull/12022 which is released under 9.7.0

### Workarounds

Configure the CORS environment variables to match your project's usage, rather than leaving them at the (permissive) defaults.

### For more information If you have any questions or comments about this advisory: * Open an issue in [directus/directus](https://github.com/directus/directus) * Email us at [security@directus.io](mailto:security@directus.io)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 0Fixed in: 9.7.0
Fixnpm install directus@9.7.0

References