Skip to main content
Vulnerability Database/CVE-2024-45596

CVE-2024-45596: Monospace Directus Information Disclosure

CVE-2024-45596 is an information disclosure vulnerability in Monospace Directus that allows unauthenticated users to access credentials of previously authenticated users. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2024-45596 Overview

CVE-2024-45596 affects Directus, a real-time API and application dashboard for managing SQL database content. The vulnerability allows an unauthenticated user to retrieve credentials of the last authenticated user through OpenID or OAuth2 authentication endpoints. The flaw exists when the authentication URL is called without a redirect query string. Directus applies its respond middleware to these endpoints, which caches GET responses under conditions that do not account for authentication callbacks. As a result, sensitive user credentials can be served from cache to any subsequent unauthenticated requester. The issue is fixed in Directus 10.13.3 and 11.1.0.

Critical Impact

An unauthenticated network attacker can retrieve the last authenticated user's credentials from a cached response, leading to account compromise via OpenID or OAuth2 flows.

Affected Products

  • Monospace Directus versions prior to 10.13.3
  • Monospace Directus 11.x versions prior to 11.1.0
  • Directus deployments with CACHE_ENABLED=true using OpenID or OAuth2 authentication

Discovery Timeline

  • 2024-09-10 - CVE-2024-45596 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-45596

Vulnerability Analysis

The vulnerability is a sensitive information disclosure flaw classified as [CWE-524] (Use of Cache Containing Sensitive Information). Directus routes both OpenID and OAuth2 authentication endpoints through a shared respond middleware located at api/src/middleware/respond.ts. When the CACHE_ENABLED environment variable is set to true, the middleware caches GET responses that meet a defined set of conditions. Those conditions do not exclude /auth routes, so a response containing user credentials returned during an OpenID or OAuth2 callback can be stored in the cache. Any subsequent unauthenticated GET request to the same endpoint receives the cached credential payload, enabling account takeover of the last authenticated user.

Root Cause

The root cause is missing path-based exclusion in the response caching logic. The respond middleware evaluated method, cache configuration, and query parameters but did not check whether the URL belonged to the authentication surface. Authentication callbacks returning sensitive tokens and user data were therefore treated as cacheable GET responses.

Attack Vector

Exploitation requires network access to the Directus API and user interaction to trigger a legitimate OpenID or OAuth2 login without a redirect query string. Once a valid authentication response is cached, an unauthenticated attacker can issue a GET request to the same authentication URL and receive the previously authenticated user's credentials directly from the cache.

typescript
// Security patch in api/src/middleware/respond.ts
	if (
		(req.method.toLowerCase() === 'get' || req.originalUrl?.startsWith('/graphql')) &&
+		req.originalUrl?.startsWith('/auth') === false &&
		env['CACHE_ENABLED'] === true &&
		cache &&
		!req.sanitizedQuery.export &&

Source: Directus commit 4aace0b. The patch adds an explicit check that skips caching whenever the request URL begins with /auth, preventing authentication responses from ever entering the cache store.

Detection Methods for CVE-2024-45596

Indicators of Compromise

  • Repeated unauthenticated GET requests to /auth/login/* endpoints from unexpected source IP addresses
  • HTTP 200 responses on /auth endpoints returning user credential payloads without an associated OpenID or OAuth2 handshake
  • Directus authentication requests missing the redirect query string parameter

Detection Strategies

  • Instrument the Directus reverse proxy or WAF to log all GET requests hitting /auth/login/oauth2 and /auth/login/openid routes and alert on requests without a corresponding upstream identity provider callback
  • Correlate authentication endpoint responses with active user sessions to identify credential payloads served to unauthenticated clients
  • Inspect deployed Directus version against the fixed releases 10.13.3 and 11.1.0 to identify vulnerable instances

Monitoring Recommendations

  • Monitor cache hit ratios on /auth routes; any cache hit on these endpoints indicates a vulnerable configuration
  • Alert on anomalous access to identity and session APIs following authentication events
  • Enable audit logging for successful authentications and compare against source IPs of subsequent requests to the same endpoint

How to Mitigate CVE-2024-45596

Immediate Actions Required

  • Upgrade Directus to version 10.13.3 or 11.1.0 or later
  • Purge the existing Directus response cache to remove any credential payloads that may already be stored
  • Rotate credentials and invalidate active sessions for users who authenticated via OpenID or OAuth2 before the upgrade

Patch Information

The fix is delivered in Directus commits 4aace0b and 769fa22, and documented in GitHub Security Advisory GHSA-cff8-x7jv-4fm8. The patch modifies the respond middleware to exclude any request whose originalUrl starts with /auth from the caching logic.

Workarounds

  • Set CACHE_ENABLED=false in the Directus environment configuration until the patched version can be deployed
  • Place a reverse proxy rule in front of Directus that strips cacheable headers from /auth/* responses and blocks unauthenticated GET requests to those routes
  • Ensure every OpenID and OAuth2 authentication URL includes a valid redirect query string parameter
bash
# Configuration example: disable response cache in Directus .env
CACHE_ENABLED="false"

# Or, if cache is required, ensure Directus is upgraded and verify version
npx directus --version
# Expected output: 10.13.3, 11.1.0, or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.