VDB
Sign up
MEDIUM4.2

GHSA-vw58-ph65-6rxp

Directus inserts access token from query string into logs

Quick fix

GHSA-vw58-ph65-6rxp — @directus/api: upgrade to the fixed version with the command below.

npm install @directus/api@21.0.0

Details

### Summary Access token from query string is not redacted and is potentially exposed in system logs which may be persisted.

### Details The access token in `req.query` is not redacted when the `LOG_STYLE` is set to `raw`. If these logs are not properly sanitized or protected, an attacker with access to it can potentially gain administrative control, leading to unauthorized data access and manipulation.

### PoC 1. Set `LOG_LEVEL="raw"` in the environment. 2. Send a request with the `access_token` in the query string. 3. Notice that the `access_token` in `req.query` is not redacted.

### Impact It impacts systems where the `LOG_STYLE` is set to `raw`. The `access_token` in the query could potentially be a long-lived static token. Users with impacted systems should rotate their static tokens if they were provided using query string.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@directus/api
Introduced in: 0Fixed in: 21.0.0
Fixnpm install @directus/api@21.0.0

References