Junglewise Threat Intelligence

CVE-2024-47822: Directus access token exposure in logs

CVE-2024-47822 · Severity: low · CVSS 3.1 · Published 2025-04-14

Technologies: @directus/api (npm). Vendors: Directus, npm.

Executive brief

Directus, a popular open-source content management and data platform, logs unredacted access tokens when the LOG_STYLE setting is configured to "raw". An attacker with access to these logs could extract long-lived authentication credentials and gain unauthorized administrative access to the system, potentially exposing or manipulating sensitive business data. Affected organizations should review their log retention and access controls, and rotate any static tokens that may have been exposed.

Technical details

This vulnerability is a sensitive information disclosure issue (CWE-532) in the Directus API where authentication tokens passed in the query string are not redacted from logs when LOG_STYLE is set to "raw". The root cause is insufficient sanitization of request parameters before logging. The attack requires local access to logs, high privileges, and user interaction (someone must make a request with the token in the query string); however, the impact is high confidentiality loss if an attacker gains access to log files containing valid tokens. The vulnerability was patched in versions 10.13.2, 11.1.0, and 21.0.0 across the affected branches.

Affected products

  • Directus directus < 10.13.2, < 11.1.0 (before 21.0.0 fix)

Timeline

  • 2024-10-08: disclosed
  • 2024: patched: Fixed in versions 10.13.2, 11.1.0, and 21.0.0

References

Related threats