Description
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0951 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3. |
Github GHSA |
GHSA-8vg2-wf3q-mwv7 | directus vulnerable to Insertion of Sensitive Information into Log File |
References
History
Fri, 21 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-21T15:30:10.767Z
Reserved: 2023-03-15T15:59:10.056Z
Link: CVE-2023-28443
Updated: 2024-08-02T12:38:25.370Z
Status : Modified
Published: 2023-03-24T00:15:15.553
Modified: 2024-11-21T07:55:05.200
Link: CVE-2023-28443
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA