SB20231019122 - Uncaught Exception in Directus
Published: October 19, 2023 Updated: April 23, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Uncaught Exception (CVE-ID: CVE-2023-45820)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper exception handling in the websocket server when processing an invalid websocket frame. A remote attacker can send a specially crafted invalid websocket frame to cause a denial of service.
Only installations with websockets enabled are vulnerable.
Remediation
Install update from vendor's website.