CVE-2023-38503
Last modified
CVE-2023-38503 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.3.0 and prior to version 10.5.0, the permission filters (i.e. `user_created IS $CURRENT_USER`) are not properly checked when using GraphQL subscription resulting in unauthorized users getting event on their subscription which they should not be receiving according to the permissions. This can be any collection but out-of-the box the `directus_users` collection is configured with such a permissions filter allowing you to get updates for other users when changes happen. Version 10.5.0 contains a patch. As a workaround, disable GraphQL subscriptions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Monospace | Directus | >= 10.3.0, < 10.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38503?
How severe is CVE-2023-38503?
How do I fix CVE-2023-38503?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-38498Discourse is an open source discussion platform. Prior to ve…6.5
- CVE-2023-38499TYPO3 is an open source PHP based web content management sys…5.3
- CVE-2023-3850A vulnerability has been found in SourceCodester Lost and Fo…9.8
- CVE-2023-38500TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, a…6.1
- CVE-2023-38501copyparty is file server software. Prior to version 1.8.7, t…6.1
- CVE-2023-38502TDengine is an open source, time-series database optimized f…6.5
- CVE-2023-38504Sails is a realtime MVC Framework for Node.js. In Sails apps…7.5
- CVE-2023-38505DietPi-Dashboard is a web dashboard for the operating system…7.5
- CVE-2023-38506Joplin is a free, open source note taking and to-do applicat…5.4
- CVE-2023-38507Strapi is the an open-source headless content management sys…9.8
- CVE-2023-38508Tuleap is an open source suite to improve management of soft…4.3
- CVE-2023-38509XWiki Platform is a generic wiki platform. In org.xwiki.plat…4.3
Are you affected by CVE-2023-38503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
