CVE-2025-53885

MEDIUM4.2EPSS 0.11%

Directus is vulnerable to sensitive data exposure as user data is not being redacted when logged

發布日:2025/7/15修改日:2025/7/15

描述

### Summary When using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string. ### Impact Malicious admins can log sensitive data from other users when they are created or updated. ### Workarounds Avoid logging sensitive data to the console outside the context of development.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.2CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

參考連結(6)