Junglewise Threat Intelligence

CVE-2024-39699: Directus blind SSRF via file import redirect bypass

CVE-2024-39699 · Severity: low · CVSS 3.1 · Published 2024-07-08

Technologies: @directus/api (npm). Vendors: Directus, npm.

Executive brief

Directus, a popular open-source headless CMS, contains a blind server-side request forgery (SSRF) vulnerability in its file import functionality. An authenticated attacker can bypass the existing SSRF protections by leveraging HTTP redirects to make Directus initiate requests to internal network addresses. While the vulnerability is "blind" (responses are not visible to the attacker), it can still be exploited to trigger vulnerable services on internal networks using simple GET requests, potentially leading to remote code execution or data exposure.

Technical details

A server-side request forgery (SSRF) vulnerability exists in Directus's file import endpoint (/files/import). The vulnerability is a bypass of prior SSRF protections (GHSA-j3rg-3rgm-537h) that checked for internal IP addresses. The flaw occurs because Directus follows HTTP redirects during file import without validating the final redirect destination against internal IP ranges. An authenticated attacker can POST to /files/import with a URL pointing to a controlled external server, which responds with a 3xx redirect to an internal IP address (e.g., 127.0.0.1 or other RFC1918 ranges). Directus will follow the redirect and send a request to the internal address. Although response contents are not returned (blind SSRF), the attacker can exploit this to trigger vulnerabilities in internal services via GET requests. Fixed in version 10.9.3 and later by disallowing redirects or validating redirect destinations.

Affected products

  • Directus Directus < 10.9.3

Timeline

  • 2024-07-08: disclosed
  • 2024-07-08: patched: Fixed in version 10.9.3

References

Related threats