directus 中的 SSRF Loopback IP 过滤器绕过(CVE-2024-46990)

admin 2024-09-19 12:01:07 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
directus 中的 SSRF Loopback IP 过滤器绕过(CVE-2024-46990)

CVE编号

CVE-2024-46990

利用情况

暂无

补丁情况

N/A

披露时间

2024-09-19
漏洞描述
Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This issue has been addressed in release versions 10.13.3 and 11.1.0. Users are advised to upgrade. Users unable to upgrade may block this bypass by manually adding the `127.0.0.0/8` CIDR range which will block access to any `127.X.X.X` ip instead of just `127.0.0.1`.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/directus/directus/commit/4aace0bbe57232e38cd6a287ee475293e46dc91b
https://github.com/directus/directus/commit/769fa22797bff5a9231599883b391e013f122e52
https://github.com/directus/directus/commit/8cbf943b65fd4a763d09a5fdbba8996b1e7797ff
https://github.com/directus/directus/commit/c1f3ccc681595038d094ce110ddeee38cb38f431
https://github.com/directus/directus/security/advisories/GHSA-68g8-c275-xf2m
CVSS3评分 5.0
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 低
  • 影响范围 已更改
  • 用户交互 无
  • 可用性 无
  • 保密性 低
  • 完整性 无
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CWE-ID 漏洞类型
CWE-284 访问控制不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2023-41610利用情况 暂无补丁情况 N/A披露时间 2024-09-19漏洞描述Victure PC420 1.1.39被
评论:0   参与:  0