CVE-2024-45596 Overview
CVE-2024-45596 affects Directus, a real-time API and application dashboard for managing SQL database content. The vulnerability allows an unauthenticated user to retrieve credentials of the last authenticated user through OpenID or OAuth2 authentication endpoints. The flaw exists when the authentication URL is called without a redirect query string. Directus applies its respond middleware to these endpoints, which caches GET responses under conditions that do not account for authentication callbacks. As a result, sensitive user credentials can be served from cache to any subsequent unauthenticated requester. The issue is fixed in Directus 10.13.3 and 11.1.0.
Critical Impact
An unauthenticated network attacker can retrieve the last authenticated user's credentials from a cached response, leading to account compromise via OpenID or OAuth2 flows.
Affected Products
- Monospace Directus versions prior to 10.13.3
- Monospace Directus 11.x versions prior to 11.1.0
- Directus deployments with CACHE_ENABLED=true using OpenID or OAuth2 authentication
Discovery Timeline
- 2024-09-10 - CVE-2024-45596 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-45596
Vulnerability Analysis
The vulnerability is a sensitive information disclosure flaw classified as [CWE-524] (Use of Cache Containing Sensitive Information). Directus routes both OpenID and OAuth2 authentication endpoints through a shared respond middleware located at api/src/middleware/respond.ts. When the CACHE_ENABLED environment variable is set to true, the middleware caches GET responses that meet a defined set of conditions. Those conditions do not exclude /auth routes, so a response containing user credentials returned during an OpenID or OAuth2 callback can be stored in the cache. Any subsequent unauthenticated GET request to the same endpoint receives the cached credential payload, enabling account takeover of the last authenticated user.
Root Cause
The root cause is missing path-based exclusion in the response caching logic. The respond middleware evaluated method, cache configuration, and query parameters but did not check whether the URL belonged to the authentication surface. Authentication callbacks returning sensitive tokens and user data were therefore treated as cacheable GET responses.
Attack Vector
Exploitation requires network access to the Directus API and user interaction to trigger a legitimate OpenID or OAuth2 login without a redirect query string. Once a valid authentication response is cached, an unauthenticated attacker can issue a GET request to the same authentication URL and receive the previously authenticated user's credentials directly from the cache.
// Security patch in api/src/middleware/respond.ts
if (
(req.method.toLowerCase() === 'get' || req.originalUrl?.startsWith('/graphql')) &&
+ req.originalUrl?.startsWith('/auth') === false &&
env['CACHE_ENABLED'] === true &&
cache &&
!req.sanitizedQuery.export &&
Source: Directus commit 4aace0b. The patch adds an explicit check that skips caching whenever the request URL begins with /auth, preventing authentication responses from ever entering the cache store.
Detection Methods for CVE-2024-45596
Indicators of Compromise
- Repeated unauthenticated GET requests to /auth/login/* endpoints from unexpected source IP addresses
- HTTP 200 responses on /auth endpoints returning user credential payloads without an associated OpenID or OAuth2 handshake
- Directus authentication requests missing the redirect query string parameter
Detection Strategies
- Instrument the Directus reverse proxy or WAF to log all GET requests hitting /auth/login/oauth2 and /auth/login/openid routes and alert on requests without a corresponding upstream identity provider callback
- Correlate authentication endpoint responses with active user sessions to identify credential payloads served to unauthenticated clients
- Inspect deployed Directus version against the fixed releases 10.13.3 and 11.1.0 to identify vulnerable instances
Monitoring Recommendations
- Monitor cache hit ratios on /auth routes; any cache hit on these endpoints indicates a vulnerable configuration
- Alert on anomalous access to identity and session APIs following authentication events
- Enable audit logging for successful authentications and compare against source IPs of subsequent requests to the same endpoint
How to Mitigate CVE-2024-45596
Immediate Actions Required
- Upgrade Directus to version 10.13.3 or 11.1.0 or later
- Purge the existing Directus response cache to remove any credential payloads that may already be stored
- Rotate credentials and invalidate active sessions for users who authenticated via OpenID or OAuth2 before the upgrade
Patch Information
The fix is delivered in Directus commits 4aace0b and 769fa22, and documented in GitHub Security Advisory GHSA-cff8-x7jv-4fm8. The patch modifies the respond middleware to exclude any request whose originalUrl starts with /auth from the caching logic.
Workarounds
- Set CACHE_ENABLED=false in the Directus environment configuration until the patched version can be deployed
- Place a reverse proxy rule in front of Directus that strips cacheable headers from /auth/* responses and blocks unauthenticated GET requests to those routes
- Ensure every OpenID and OAuth2 authentication URL includes a valid redirect query string parameter
# Configuration example: disable response cache in Directus .env
CACHE_ENABLED="false"
# Or, if cache is required, ensure Directus is upgraded and verify version
npx directus --version
# Expected output: 10.13.3, 11.1.0, or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.