Inclusion of Sensitive Information in Log Files in Directus - CVE-2024-47822

 

Inclusion of Sensitive Information in Log Files in Directus - CVE-2024-47822

Published: October 8, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127108
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47822
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log files in request query logging when handling requests with an access token in the query string while raw logging is enabled. A local privileged user can send a request containing an access token in the query string to disclose sensitive information.

Only instances with LOG_STYLE set to raw are vulnerable. User interaction is required.


Affected software

Directus

How to mitigate CVE-2024-47822

Install security update from vendor's website.

Directus - addressed in versions 10.13.2, 11.1.0

External References

Related Security Bulletins