GHSA-q83v-hq3j-4pq3

Suggest an improvement
Source
https://github.com/advisories/GHSA-q83v-hq3j-4pq3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-q83v-hq3j-4pq3/GHSA-q83v-hq3j-4pq3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q83v-hq3j-4pq3
Withdrawn
2025-03-20T18:34:46Z
Published
2024-08-15T06:32:22Z
Modified
2025-03-20T18:34:46Z
Severity
  • 4.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
Duplicate Advisory: Improper access control in Directus
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-3fff-gqw3-vj86. This link is maintained to preserve external references.

Original Description

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.

Database specific
{
    "cwe_ids":  [
        "CWE-639"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-08-15T21:56:16Z",
    "nvd_published_at":  "2024-08-15T04:15:07Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / directus

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
10.13.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-q83v-hq3j-4pq3/GHSA-q83v-hq3j-4pq3.json"