CVE-2024-28239

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Mar 12, 2024
Updated: Mar 13, 2024
CWE ID 601

Summary

CVE-2024-28239 is a vulnerability affecting Directus, a real-time API and App dashboard for managing SQL database content. The authentication API contains an open redirect vulnerability, which can be exploited by manipulating the `redirect` parameter in the login process. Successful login attempts via the Auth API GET request lead users to a maliciously crafted URL, such as "directus/auth/login/google?redirect=http://malicious-fishing-site.com". Although credentials are not directly exposed, users may be tricked into clicking a seemingly legitimate Directus site, only to be redirected to a phishing site disguised as an error message requesting password updates. Users who log in via OAuth2 into Directus are at risk. Version 10.10.0 of Directus addresses this issue, and users are advised to upgrade as soon as possible. There are currently no known workarounds for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share