In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.
[
{
"product": "directus",
"vendor": "directus",
"versions": [
{
"lessThan": "unspecified",
"status": "affected",
"version": "v9.0.0-beta.10",
"versionType": "custom"
},
{
"lessThanOrEqual": "v9.6.0",
"status": "affected",
"version": "unspecified",
"versionType": "custom"
}
]
}
]