Insecure Defaults Affecting directus package, versions <9.7.0
Threat Intelligence
EPSS
0.2% (58th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-DIRECTUS-2441822
- published 7 Apr 2022
- disclosed 5 Apr 2022
- credit Rijk van Zanten
Introduced: 5 Apr 2022
CVE-2022-26969 Open this link in a new tabHow to fix?
Upgrade directus
to version 9.7.0 or higher.
Overview
directus is a Directus is a real-time API and App dashboard for managing SQL database content.
Affected versions of this package are vulnerable to Insecure Defaults via the default value for the CORS_ENABLED
and CORS_ORIGIN
configuration, which was set to be very permissive.
Workaround
It is possible to configure the CORS
environment variables to match your project's usage, instead of leaving them as is.
References
CVSS Scores
version 3.1