Executive brief
Directus, a popular headless CMS and backend platform, was leaking its software version number in publicly accessible compiled code files. An attacker could easily discover which version is running and then look up known security vulnerabilities in that version or its included libraries, significantly improving their chances of finding an exploitable weakness.
Technical details
The vulnerability is an information disclosure (CWE-200) where Directus version strings are hardcoded and shipped within compiled JavaScript bundles that are accessible over the network without authentication. The attack vector is network-based with no authentication required, allowing an unauthenticated remote attacker to retrieve the version number from publicly served assets. By knowing the exact version, an attacker can trivially enumerate known CVEs in Directus core and its dependencies to facilitate further exploitation. The issue was patched in version 10.8.3 by removing hardcoded version references from the compiled application code.
Affected products
- Directus Directus <=10.8.2
Timeline
- 2024-03-01: disclosed
- 2024-03-01: patched: Fixed in version 10.8.3