mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
20 lines
1.1 KiB
Markdown
20 lines
1.1 KiB
Markdown
### [CVE-2023-28443](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28443)
|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/directus/directus/commit/349536303983ccba68ecb3e4fb35315424011afc
|
|
- https://github.com/directus/directus/security/advisories/GHSA-8vg2-wf3q-mwv7
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|