Directus是一个实时 Api 和应用程序仪表板。用于管理 Sql 数据库内容。 Directus存在安全漏洞。攻击者利用该漏洞可以枚举实例中的现有SSO用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-39895 | 6.5 MEDIUM | Directus GraphQL Field Duplication Denial of Service (DoS) |
| CVE-2024-39701 | 6.3 MEDIUM | Directus Incorrectly handles _in` filter |
| CVE-2024-39699 | 5.0 MEDIUM | Directus has a Blind SSRF On File Import |
No comments yet