SB20240708107 - Information disclosure in Directus



SB20240708107 - Information disclosure in Directus

Published: July 8, 2024 Updated: April 23, 2026

Security Bulletin ID SB20240708107
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2024-39896)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the login form and authentication API when handling login attempts for email addresses associated with SSO providers. A remote attacker can submit a login request with a targeted email address to disclose sensitive information.

The issue occurs when SSO providers are used in combination with local authentication.


Remediation

Install update from vendor's website.