mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-11 20:52:49 +02:00
1.1 KiB
1.1 KiB
CVE-2023-28443
Description
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the directus_refresh_token is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.
POC
Reference
- https://github.com/directus/directus/commit/349536303983ccba68ecb3e4fb35315424011afc
- https://github.com/directus/directus/security/advisories/GHSA-8vg2-wf3q-mwv7
Github
No PoCs found on GitHub currently.