Executive brief
Directus, a popular open-source headless CMS platform, contains an open redirect vulnerability in its OAuth2/OpenID login flow. Attackers can craft malicious login links that, after successful authentication, redirect users to attacker-controlled sites designed to appear as legitimate error pages, enabling credential phishing attacks. This vulnerability affects users authenticating through OAuth2 providers.
Technical details
The vulnerability exists in the authentication API's redirect parameter (e.g., /auth/login/google?redirect=...) which fails to properly validate redirect destinations. An attacker can craft a URL with a redirect parameter pointing to a malicious domain. After the user successfully authenticates via OAuth2, the application redirects them to the attacker's site without validation. The vulnerable code is in the oauth2.ts driver. The attack requires user interaction (clicking the crafted link) but no authentication or special privileges. An attacker can exploit this to redirect authenticated users to phishing sites mimicking password reset pages to steal credentials. The issue was patched in version 10.10.0.
Affected products
- Directus Directus <10.10.0
Timeline
- 2024-03-12: disclosed
- 2024-03-12: patched: Fixed in version 10.10.0