Security Advisory

CVE-2022-23080

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-06-22 15:40:10
Last updated 2024-09-17 02:22:06
Assigner Mend
CVSS score not scored
State PUBLISHED

Description

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.