Directus是Directus开源的一个实时 Api 和应用程序仪表板。用于管理 Sql 数据库内容。 Directus 9.0.0至11.9.0之前版本存在信息泄露漏洞,该漏洞源于暴露版本信息,可能导致已知漏洞利用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Directus versions from 9.0.0 before 11.9.0 expose the exact running version through the OpenAPI specification returned by the unauthenticated /server/specs/oas endpoint. The version is placed in the OpenAPI info.version field, letting an unauthenticated attacker fingerprint the precise Directus release. The fix replaces the exact version in that field with a hashed value. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-53887.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-53889 | 6.5 MEDIUM | Directus missing permission checks for manual trigger Flows |
| CVE-2025-53886 | 4.5 MEDIUM | Directus doesn't redact tokens in Flow logs |
| CVE-2025-53885 | 4.2 MEDIUM | Directus doesn't redact sensitive user data when logging via event hooks |
No comments yet