In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password reset feature. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/sgranel/directusv8 |
|
History
Tue, 24 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T21:26:10.369Z
Reserved: 2021-02-23T00:00:00.000Z
Link: CVE-2021-27583
Updated: 2024-08-03T21:26:10.369Z
Status : Modified
Published: 2021-02-23T19:15:14.213
Modified: 2024-11-21T05:58:14.193
Link: CVE-2021-27583
No data.
OpenCVE Enrichment
No data.
Weaknesses