Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36094
HistoryJun 23, 2022 - 7:56 a.m.

Server-Side Request Forgery (SSRF)

2022-06-2307:56:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.001 Low

EPSS

Percentile

21.6%

directus is vulnerable to server-side request forgery. The vulnerability exists in the media upload functionality because it doesn’t allows to configure specific IP addresses to be deny-listed from being imported which allows an attacker to perform network portal scans internally.

CPENameOperatorVersion
directusle9.6.0
directusle9.6.0

0.001 Low

EPSS

Percentile

21.6%