{"id":"CVE-2024-46990","aliases":["GHSA-68g8-c275-xf2m"],"url":"https://o3.security/vulnerability/CVE-2024-46990","summary":"SSRF Loopback IP filter bypass in directus","details":"Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter a user may bypass this block by using other registered loopback devices (like `127.0.0.2` - `127.127.127.127`). This issue has been addressed in release versions 10.13.3 and 11.1.0. Users are advised to upgrade. Users unable to upgrade may block this bypass by manually adding the `127.0.0.0/8` CIDR range which will block access to any `127.X.X.X` ip instead of just `127.0.0.1`.","published":"2024-09-18T16:55:24.255Z","modified":"2026-08-12T03:51:37.055618315Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"directus","fixedVersion":"10.13.3"},{"ecosystem":"npm","name":"directus","fixedVersion":"11.1.0"},{"ecosystem":"npm","name":"@directus/api","fixedVersion":"21.0.0"},{"ecosystem":"npm","name":"@directus/api","fixedVersion":"22.1.1"}],"fix":{"url":"https://github.com/directus/directus/commit/4aace0bbe57232e38cd6a287ee475293e46dc91b","label":"directus/directus@4aace0b"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46990.json"},{"type":"ADVISORY","url":"https://github.com/directus/directus/security/advisories/GHSA-68g8-c275-xf2m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46990"},{"type":"FIX","url":"https://github.com/directus/directus/commit/4aace0bbe57232e38cd6a287ee475293e46dc91b"},{"type":"FIX","url":"https://github.com/directus/directus/commit/769fa22797bff5a9231599883b391e013f122e52"},{"type":"FIX","url":"https://github.com/directus/directus/commit/8cbf943b65fd4a763d09a5fdbba8996b1e7797ff"},{"type":"FIX","url":"https://github.com/directus/directus/commit/c1f3ccc681595038d094ce110ddeee38cb38f431"},{"type":"PACKAGE","url":"https://github.com/directus/directus"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.055618315Z"}}