CVE Vulnerabilities

CVE-2022-23080

Server-Side Request Forgery (SSRF)

Published: Jun 22, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media upload functionality which allows a low privileged user to perform internal network port scans.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

NameVendorStart VersionEnd Version
DirectusRangerstudio9.0.1 (including)9.6.0 (including)
DirectusRangerstudio9.0.0-beta10 (including)9.0.0-beta10 (including)
DirectusRangerstudio9.0.0-beta11 (including)9.0.0-beta11 (including)
DirectusRangerstudio9.0.0-beta12 (including)9.0.0-beta12 (including)
DirectusRangerstudio9.0.0-beta13 (including)9.0.0-beta13 (including)
DirectusRangerstudio9.0.0-beta14 (including)9.0.0-beta14 (including)
DirectusRangerstudio9.0.0-beta2 (including)9.0.0-beta2 (including)
DirectusRangerstudio9.0.0-beta3 (including)9.0.0-beta3 (including)
DirectusRangerstudio9.0.0-beta4 (including)9.0.0-beta4 (including)
DirectusRangerstudio9.0.0-beta5 (including)9.0.0-beta5 (including)
DirectusRangerstudio9.0.0-beta7 (including)9.0.0-beta7 (including)
DirectusRangerstudio9.0.0-beta8 (including)9.0.0-beta8 (including)
DirectusRangerstudio9.0.0-beta9 (including)9.0.0-beta9 (including)
DirectusRangerstudio9.0.0-rc0 (including)9.0.0-rc0 (including)
DirectusRangerstudio9.0.0-rc1 (including)9.0.0-rc1 (including)
DirectusRangerstudio9.0.0-rc10 (including)9.0.0-rc10 (including)
DirectusRangerstudio9.0.0-rc100 (including)9.0.0-rc100 (including)
DirectusRangerstudio9.0.0-rc101 (including)9.0.0-rc101 (including)
DirectusRangerstudio9.0.0-rc11 (including)9.0.0-rc11 (including)
DirectusRangerstudio9.0.0-rc12 (including)9.0.0-rc12 (including)
DirectusRangerstudio9.0.0-rc13 (including)9.0.0-rc13 (including)
DirectusRangerstudio9.0.0-rc14 (including)9.0.0-rc14 (including)
DirectusRangerstudio9.0.0-rc15 (including)9.0.0-rc15 (including)
DirectusRangerstudio9.0.0-rc17 (including)9.0.0-rc17 (including)
DirectusRangerstudio9.0.0-rc18 (including)9.0.0-rc18 (including)
DirectusRangerstudio9.0.0-rc19 (including)9.0.0-rc19 (including)
DirectusRangerstudio9.0.0-rc2 (including)9.0.0-rc2 (including)
DirectusRangerstudio9.0.0-rc20 (including)9.0.0-rc20 (including)
DirectusRangerstudio9.0.0-rc21 (including)9.0.0-rc21 (including)
DirectusRangerstudio9.0.0-rc22 (including)9.0.0-rc22 (including)
DirectusRangerstudio9.0.0-rc23 (including)9.0.0-rc23 (including)
DirectusRangerstudio9.0.0-rc24 (including)9.0.0-rc24 (including)
DirectusRangerstudio9.0.0-rc25 (including)9.0.0-rc25 (including)
DirectusRangerstudio9.0.0-rc26 (including)9.0.0-rc26 (including)
DirectusRangerstudio9.0.0-rc27 (including)9.0.0-rc27 (including)
DirectusRangerstudio9.0.0-rc28 (including)9.0.0-rc28 (including)
DirectusRangerstudio9.0.0-rc29 (including)9.0.0-rc29 (including)
DirectusRangerstudio9.0.0-rc3 (including)9.0.0-rc3 (including)
DirectusRangerstudio9.0.0-rc30 (including)9.0.0-rc30 (including)
DirectusRangerstudio9.0.0-rc31 (including)9.0.0-rc31 (including)
DirectusRangerstudio9.0.0-rc32 (including)9.0.0-rc32 (including)
DirectusRangerstudio9.0.0-rc33 (including)9.0.0-rc33 (including)
DirectusRangerstudio9.0.0-rc34 (including)9.0.0-rc34 (including)
DirectusRangerstudio9.0.0-rc35 (including)9.0.0-rc35 (including)
DirectusRangerstudio9.0.0-rc36 (including)9.0.0-rc36 (including)
DirectusRangerstudio9.0.0-rc37 (including)9.0.0-rc37 (including)
DirectusRangerstudio9.0.0-rc38 (including)9.0.0-rc38 (including)
DirectusRangerstudio9.0.0-rc39 (including)9.0.0-rc39 (including)
DirectusRangerstudio9.0.0-rc4 (including)9.0.0-rc4 (including)
DirectusRangerstudio9.0.0-rc40 (including)9.0.0-rc40 (including)
DirectusRangerstudio9.0.0-rc41 (including)9.0.0-rc41 (including)
DirectusRangerstudio9.0.0-rc42 (including)9.0.0-rc42 (including)
DirectusRangerstudio9.0.0-rc43 (including)9.0.0-rc43 (including)
DirectusRangerstudio9.0.0-rc44 (including)9.0.0-rc44 (including)
DirectusRangerstudio9.0.0-rc45 (including)9.0.0-rc45 (including)
DirectusRangerstudio9.0.0-rc46 (including)9.0.0-rc46 (including)
DirectusRangerstudio9.0.0-rc47 (including)9.0.0-rc47 (including)
DirectusRangerstudio9.0.0-rc48 (including)9.0.0-rc48 (including)
DirectusRangerstudio9.0.0-rc49 (including)9.0.0-rc49 (including)
DirectusRangerstudio9.0.0-rc5 (including)9.0.0-rc5 (including)
DirectusRangerstudio9.0.0-rc50 (including)9.0.0-rc50 (including)
DirectusRangerstudio9.0.0-rc51 (including)9.0.0-rc51 (including)
DirectusRangerstudio9.0.0-rc52 (including)9.0.0-rc52 (including)
DirectusRangerstudio9.0.0-rc53 (including)9.0.0-rc53 (including)
DirectusRangerstudio9.0.0-rc54 (including)9.0.0-rc54 (including)
DirectusRangerstudio9.0.0-rc55 (including)9.0.0-rc55 (including)
DirectusRangerstudio9.0.0-rc56 (including)9.0.0-rc56 (including)
DirectusRangerstudio9.0.0-rc57 (including)9.0.0-rc57 (including)
DirectusRangerstudio9.0.0-rc58 (including)9.0.0-rc58 (including)
DirectusRangerstudio9.0.0-rc59 (including)9.0.0-rc59 (including)
DirectusRangerstudio9.0.0-rc6 (including)9.0.0-rc6 (including)
DirectusRangerstudio9.0.0-rc60 (including)9.0.0-rc60 (including)
DirectusRangerstudio9.0.0-rc61 (including)9.0.0-rc61 (including)
DirectusRangerstudio9.0.0-rc62 (including)9.0.0-rc62 (including)
DirectusRangerstudio9.0.0-rc63 (including)9.0.0-rc63 (including)
DirectusRangerstudio9.0.0-rc64 (including)9.0.0-rc64 (including)
DirectusRangerstudio9.0.0-rc65 (including)9.0.0-rc65 (including)
DirectusRangerstudio9.0.0-rc66 (including)9.0.0-rc66 (including)
DirectusRangerstudio9.0.0-rc67 (including)9.0.0-rc67 (including)
DirectusRangerstudio9.0.0-rc68 (including)9.0.0-rc68 (including)
DirectusRangerstudio9.0.0-rc69 (including)9.0.0-rc69 (including)
DirectusRangerstudio9.0.0-rc7 (including)9.0.0-rc7 (including)
DirectusRangerstudio9.0.0-rc70 (including)9.0.0-rc70 (including)
DirectusRangerstudio9.0.0-rc71 (including)9.0.0-rc71 (including)
DirectusRangerstudio9.0.0-rc72 (including)9.0.0-rc72 (including)
DirectusRangerstudio9.0.0-rc73 (including)9.0.0-rc73 (including)
DirectusRangerstudio9.0.0-rc74 (including)9.0.0-rc74 (including)
DirectusRangerstudio9.0.0-rc75 (including)9.0.0-rc75 (including)
DirectusRangerstudio9.0.0-rc76 (including)9.0.0-rc76 (including)
DirectusRangerstudio9.0.0-rc77 (including)9.0.0-rc77 (including)
DirectusRangerstudio9.0.0-rc78 (including)9.0.0-rc78 (including)
DirectusRangerstudio9.0.0-rc79 (including)9.0.0-rc79 (including)
DirectusRangerstudio9.0.0-rc8 (including)9.0.0-rc8 (including)
DirectusRangerstudio9.0.0-rc80 (including)9.0.0-rc80 (including)
DirectusRangerstudio9.0.0-rc81 (including)9.0.0-rc81 (including)
DirectusRangerstudio9.0.0-rc82 (including)9.0.0-rc82 (including)
DirectusRangerstudio9.0.0-rc83 (including)9.0.0-rc83 (including)
DirectusRangerstudio9.0.0-rc84 (including)9.0.0-rc84 (including)
DirectusRangerstudio9.0.0-rc85 (including)9.0.0-rc85 (including)
DirectusRangerstudio9.0.0-rc86 (including)9.0.0-rc86 (including)
DirectusRangerstudio9.0.0-rc87 (including)9.0.0-rc87 (including)
DirectusRangerstudio9.0.0-rc88 (including)9.0.0-rc88 (including)
DirectusRangerstudio9.0.0-rc89 (including)9.0.0-rc89 (including)
DirectusRangerstudio9.0.0-rc9 (including)9.0.0-rc9 (including)
DirectusRangerstudio9.0.0-rc90 (including)9.0.0-rc90 (including)
DirectusRangerstudio9.0.0-rc91 (including)9.0.0-rc91 (including)
DirectusRangerstudio9.0.0-rc92 (including)9.0.0-rc92 (including)
DirectusRangerstudio9.0.0-rc93 (including)9.0.0-rc93 (including)
DirectusRangerstudio9.0.0-rc94 (including)9.0.0-rc94 (including)
DirectusRangerstudio9.0.0-rc95 (including)9.0.0-rc95 (including)
DirectusRangerstudio9.0.0-rc96 (including)9.0.0-rc96 (including)
DirectusRangerstudio9.0.0-rc97 (including)9.0.0-rc97 (including)
DirectusRangerstudio9.0.0-rc98 (including)9.0.0-rc98 (including)
DirectusRangerstudio9.0.0-rc99 (including)9.0.0-rc99 (including)

References