Directus is a real-time API and App dashboard for managing SQL database content. In affected versions any Directus installation that has websockets enabled can be crashed if the websocket server receives an invalid frame. A malicious user could leverage this bug to crash Directus. This issue has been addressed in version 10.6.2. Users are advised to upgrade. Users unable to upgrade should avoid using websockets.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2023-10-19 19:15
Updated : 2024-11-21 08:27
NVD link : CVE-2023-45820
Mitre link : CVE-2023-45820
CVE.ORG link : CVE-2023-45820
JSON object : View
Products Affected
                monospace
- directus
CWE
                
                    
                        
                        CWE-755
                        
            Improper Handling of Exceptional Conditions
