Aqua Vulnerability Database
Get Demo
Vulnerabilities
Misconfiguration
Runtime Security
Compliance
CVE Vulnerabilities
CVE-2022-26969
Published:
Dec 26, 2022
| Modified:
Jan 05, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
Additional information
NVD
https://nvd.nist.gov/vuln/detail/CVE-2022-26969
CWE
https://cwe.mitre.org/data/definitions/.html
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
Affected Software
Name
Vendor
Start Version
End Version
Directus
Monospace
*
9.7.0 (excluding)
References
https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS
https://github.com/directus/directus/blob/8daed9c41baeaf1d08c1e292bf9f0dcef65e48fb/docs/configuration/config-options.md
https://github.com/directus/directus/pull/12022
https://github.com/directus/directus/releases/tag/v9.7.0
https://security.snyk.io/vuln/SNYK-JS-DIRECTUS-2441822
Aqua Container Security