Sploitus

CVE-2024-34709

No indexed exploits for CVE-2024-34709 yet

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if the cookie value is captured, it will still work for the entire expiry time which is set to 1 day by default. Making it effectively a long lived unrevokable stateless token instead of the stateful session token it was meant to be. This vulnerability is fixed in 10.11.0.

Affected products
Directus
Monospace Directus
< 10.11.0
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.4% (37th percentile)
Weakness
CWE-613
NVD status
Analyzed
Published
2024-05-13
CVE-2024-34709 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-34709 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-34709 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.