First published: Mon Dec 26 2022(Updated: )
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
monospace Directus | <9.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-26969.
The severity of CVE-2022-26969 is critical with a CVSS score of 9.8.
Directus is a headless CMS (Content Management System) framework.
The default settings of CORS_ORIGIN and CORS_ENABLED are true in Directus before version 9.7.0.
To fix the vulnerability, upgrade to Directus version 9.7.0 or higher.