Junglewise Threat Intelligence

CVE-2024-45596: Directus session caching vulnerability in OpenID and OAuth2

CVE-2024-45596 · Severity: low · CVSS 3.1 · Published 2024-09-10

Vendors: Directus.

Executive brief

Directus is a headless CMS platform that allows authentication via OpenID and OAuth2 protocols. When caching is enabled and the authentication URL omits the redirect parameter, the system incorrectly caches authenticated user credentials. An unauthenticated attacker can retrieve the cached credentials of the last user who logged in, gaining unauthorized access to their account and data.

Technical details

The vulnerability exists in the OpenID and OAuth2 authentication drivers (openid.ts and oauth2.ts), which rely on the respond middleware for response caching. The middleware caches GET requests based on certain conditions but fails to exclude unauthenticated requests that return sensitive user credentials (access tokens). When a user logs in via an SSO callback URL without a redirect query parameter and caching is enabled, the response containing the user's access token is cached. Subsequent unauthenticated requests to the same callback URL return the cached credentials, allowing session hijacking. This requires cache to be enabled and affects all versions of directus before 10.13.3, 11.1.0, and @directus/api before 21.0.1 and 22.2.0. The attack is network-accessible, requires user interaction (a victim must log in first), and results in credential disclosure to an unauthenticated attacker.

Affected products

  • Directus directus <=10.13.2, 11.0.0-rc.1 to <=11.0.2
  • Directus @directus/api all versions up to <21.0.1, 22.0.0 to <22.2.0

Timeline

  • 2024-09-10: disclosed: CVE-2024-45596 published
  • 2024-09-10: patched: Patches released: directus 10.13.3, 11.1.0; @directus/api 21.0.1, 22.2.0

References