Exploit maturity not defined.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade @directus/api
to version 23.1.0 or higher.
@directus/api is a real-time API and App dashboard for managing SQL database content
Affected versions of this package are vulnerable to Incorrect Authorization in the validateItemAccess
behavior in validate-item-access.js
, when applying overlapping policies to the same user. A user with read but not update permissions is able to modify unintended fields.