Lucene search

K
osvGoogleOSV:GHSA-5H75-PVQ4-82C9
HistoryJun 23, 2022 - 12:00 a.m.

Server-Side Request Forgery in Directus

2022-06-2300:00:33
Google
osv.dev
8

0.001 Low

EPSS

Percentile

21.6%

Directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality, which allows a low privileged user to perform internal network port scans.

CPENameOperatorVersion
directuslt9.7.0
directusge9.0.0-beta.2

0.001 Low

EPSS

Percentile

21.6%

Related for OSV:GHSA-5H75-PVQ4-82C9