CVE-2021-26595
Last modified
CVE-2021-26595 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rangerstudio | Directus | >= 8.0.0, <= 8.8.1 |
References
- https://github.com/sgranel/directusv8Exploit, Third Party Advisory
- https://github.com/sgranel/directusv8Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26595?
How severe is CVE-2021-26595?
How do I fix CVE-2021-26595?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26586A potential security vulnerability has been identified in th…7.5
- CVE-2021-26587A potential DOM-based Cross Site Scripting security vulnerab…6.5
- CVE-2021-26588A potential security vulnerability has been identified in HP…9.8
- CVE-2021-26589A potential security vulnerability has been identified in HP…6.1
- CVE-2021-26593In Directus 8.x through 8.8.1, an attacker can see all users…7.5
- CVE-2021-26594In Directus 8.x through 8.8.1, an attacker can switch to the…8.8
- CVE-2021-26596An issue was discovered in Nokia NetAct 18A. A malicious use…5.4
- CVE-2021-26597An issue was discovered in Nokia NetAct 18A. A remote user, …6.5
- CVE-2021-26598ImpressCMS before 1.4.3 has Incorrect Access Control because…5.3
- CVE-2021-26599ImpressCMS before 1.4.3 allows include/findusers.php groups …9.8
- CVE-2021-26600ImpressCMS before 1.4.3 has plugins/preloads/autologin.php t…9.8
- CVE-2021-26601ImpressCMS before 1.4.3 allows libraries/image-editor/image-…8.1
Are you affected by CVE-2021-26595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
