CVE-2023-45820
Summary
| CVE | CVE-2023-45820 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-19 19:15:00 UTC |
| Updated | 2023-10-25 20:27:00 UTC |
| Description | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could leverage this bug to crash Directus. This issue has been addressed in version 10.6.2. Users are advised to upgrade. Users unable to upgrade should avoid using websockets. |
Risk And Classification
Problem Types: CWE-755
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-hmgw-9jrg-hf2m · directus/directus@243eed7 · GitHub | MISC | github.com | |
| Directus crashes on invalid WebSocket message · Advisory · directus/directus · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995648 NodeJs (Npm) Security Update for directus (GHSA-hmgw-9jrg-hf2m)