CVE-2023-26492: Directus vulnerable to Server-Side Request Forgery On File Import
Directus is a real-time API and App dashboard for managing SQL database content. Directus is vulnerable to Server-Side Request Forgery (SSRF) when importing a file from a remote web server (POST to /files/import). An attacker can bypass the security controls by performing a DNS rebinding attack and view sensitive data from internal servers or perform a local port scan. An attacker can exploit this vulnerability to access highly sensitive internal server(s) and steal sensitive information. This issue was fixed in version 9.23.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-26492?
CVE-2023-26492 refers to a vulnerability in Directus, a real-time API and App dashboard for managing SQL database content, that allows for Server-Side Request Forgery (SSRF) when importing a file from a remote web server.
What is the severity of CVE-2023-26492?
The severity of CVE-2023-26492 is high, with a severity value of 7.5.
How does CVE-2023-26492 affect Directus?
CVE-2023-26492 affects Directus by allowing an attacker to perform a DNS rebinding attack and bypass security controls when importing a file from a remote web server.
Which version of Directus is affected by CVE-2023-26492?
Directus version 9.23.0 and earlier are affected by CVE-2023-26492.
How can I mitigate the vulnerability in Directus?
To mitigate the vulnerability in Directus, update to version 9.23.0 or later.