CVE-2019-13983: Critical severity rangerstudio directus 7 api vulnerability
Published Jul 19, 2019
·Updated
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
Affected Software
1 affected component
Rangerstudio Directus 7 Api<2.2.2
Remediation
Patch Available
Event History
Jul 19, 2019
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13983?
CVE-2019-13983 is categorized as a medium severity vulnerability due to insufficient anti-automation measures.
2
How do I fix CVE-2019-13983?
To fix CVE-2019-13983, upgrade Directus 7 API to version 2.2.2 or later.
3
What are the consequences of CVE-2019-13983?
CVE-2019-13983 could allow attackers to perform automated attacks on the Directus 7 API due to the lack of CAPTCHA.
4
Which versions of Directus 7 API are affected by CVE-2019-13983?
CVE-2019-13983 affects all versions of Directus 7 API prior to 2.2.2.
5
Is CVE-2019-13983 a remote or local vulnerability?
CVE-2019-13983 is a remote vulnerability as it can be exploited over the network without physical access.