VDB
Sign up
MEDIUM4.2

GHSA-x3vm-88hf-gpxp

Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged

Quick fix

GHSA-x3vm-88hf-gpxp — directus: upgrade to the fixed version with the command below.

npm install directus@11.9.0

Details

### Summary

When using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string.

### Impact

Malicious admins can log sensitive data from other users when they are created or updated.

### Workarounds Avoid logging sensitive data to the console outside the context of development.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/directus
Introduced in: 9.0.0Fixed in: 11.9.0
Fixnpm install directus@11.9.0

References