GHSA-vw58-ph65-6rxp
Directus inserts access token from query string into logs
Quick fix
GHSA-vw58-ph65-6rxp — @directus/api: upgrade to the fixed version with the command below.
npm install @directus/api@21.0.0Details
### Summary Access token from query string is not redacted and is potentially exposed in system logs which may be persisted.
### Details The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly sanitized or protected, an attacker with access to it can potentially gain administrative control, leading to unauthorized data access and manipulation.
### PoC 1. Set `LOG_LEVEL="raw"` in the environment. 2. Send a request with the `access_token` in the query string. 3. Notice that the `access_token` in `req.query` is not redacted.
### Impact It impacts systems where the `LOG_STYLE` is set to `raw`. The `access_token` in the query could potentially be a long-lived static token. Users with impacted systems should rotate their static tokens if they were provided using query string.
Are you affected?
Enter the version of the package you're using.