Executive brief
Directus API, a tool used to connect databases to web and mobile applications, is vulnerable to a denial-of-service attack. An attacker can overwhelm the system with a large volume of requests, potentially making the API and the connected applications unavailable to legitimate users. This could disrupt business operations and prevent customers from accessing data or services.
Technical details
A denial of service (DoS) vulnerability exists in Directus API v2.2.0 due to improper resource management (CWE-400). A remote attacker with low privileges can exploit this by sending a large volume of HTTP requests to the API, exhausting server resources and leading to a service outage. The vulnerability is addressed in version 2.2.1. Note that this affects the legacy v8-archive version of the Directus API.
Affected products
- Directus Directus API 2.2.0
Timeline
- 2023-04-04: advisory: NVD publication date
- 2023-04-04: disclosed: GHSA publication date