Security Advisory

CVE-2021-26594

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-23 18:59:27
Last updated 2024-08-03 20:26:25
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer