CVE-2024-27296 MEDIUM

CVE-2024-27296: Directus version number disclosure

Vendor Directus
Product directus
Weakness CWE-200 · Info exposure
Published March 1, 2024
Last update August 8, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a malicious attacker can trivially look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. The problem has been resolved in versions 10.8.3 and newer.

Key dates

02Disclosure timeline

March 1, 2024 CVE published
August 8, 2024 Record updated