Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f24x-rm6g-3w5v

Опубликовано: 15 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.5

Описание

Directus tokens are not redacted in flow logs, exposing session credentials to all admin

Summary

When using Directus Flows with the WebHook trigger, all incoming request details are logged including security sensitive data like access and refresh tokens in cookies.

Impact

Malicious admins with access to the logs can hijack the user sessions within the token expiration time of them triggering the Flow.

Пакеты

Наименование

directus

npm
Затронутые версииВерсия исправления

< 11.9.0

11.9.0

EPSS

Процентиль: 15%
0.00047
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 4.5
nvd
7 месяцев назад

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious admins with access to the logs can hijack the user sessions within the token expiration time of them triggering the Flow. Version 11.9.0 fixes the issue.

EPSS

Процентиль: 15%
0.00047
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532