漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
Vulnerability Description
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass redirect allow-list validation and redirect users to arbitrary external domains upon successful authentication. This vulnerability is fixed in 11.16.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
不完整的黑名单
Vulnerability Title
Directus 输入验证错误漏洞
Vulnerability Description
Directus是Directus开源的一个实时 Api 和应用程序仪表板。用于管理 Sql 数据库内容。 Directus 11.16.1之前版本存在输入验证错误漏洞,该漏洞源于isLoginRedirectAllowed函数未能正确识别某些畸形URL,可能导致开放重定向攻击。
CVSS Information
N/A
Vulnerability Type
N/A