CVE-2023-28443

MEDIUM

Directus <9.23.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.

Scores

CVSS v3 4.2
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-532
Status published
Products (2)
monospace/directus < 9.23.3
npm/directus 0 - 9.23.3npm
Published Mar 24, 2023
Tracked Since Feb 18, 2026