@directus/app@9.0.0-rc.78 vulnerabilities

App dashboard for Directus

  • latest version

    13.7.1

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @directus/app package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Privilege Management

    @directus/app is an App dashboard for Directus

    Affected versions of this package are vulnerable to Improper Privilege Management via the Share feature. An attacker can escalate privileges and access data or functionalities that are normally restricted by specifying an arbitrary role during the item sharing process. This is only exploitable if the instance uses the share feature and has specific roles hierarchy and fields that are not visible for certain roles.

    How to fix Improper Privilege Management?

    Upgrade @directus/app to version 13.3.1 or higher.

    <13.3.1