Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8235 | Directus `search` query parameter allows enumeration of non permitted fields |
Github GHSA |
GHSA-7wq3-jr35-275c | Directus `search` query parameter allows enumeration of non permitted fields |
Tue, 26 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Monospace
Monospace directus |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha10:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha11:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha12:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha13:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha14:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha15:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha16:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha17:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha18:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha19:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha20:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha21:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha22:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha23:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha24:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha25:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha26:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha27:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha31:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha32:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha33:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha34:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha35:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha36:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha37:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha38:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha39:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha40:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha41:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha42:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha4:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha5:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha6:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha7:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha8:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:alpha9:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta0:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta10:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta11:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta12:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta13:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta14:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta1:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta2:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta3:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta4:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta5:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta7:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta8:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:beta9:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc0:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc100:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc101:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc10:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc11:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc12:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc13:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc14:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc15:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc17:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc18:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc19:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc1:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc20:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc21:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc22:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc23:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc24:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc25:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc26:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc27:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc28:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc29:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc2:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc30:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc31:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc32:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc33:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc34:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc35:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc36:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc37:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc38:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc39:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc3:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc40:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc41:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc42:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc43:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc44:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc45:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc46:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc47:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc48:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc49:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc4:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc50:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc51:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc52:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc53:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc54:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc55:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc56:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc57:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc58:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc59:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc5:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc60:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc61:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc62:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc63:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc64:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc65:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc66:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc67:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc68:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc69:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc6:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc70:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc71:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc72:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc73:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc74:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc75:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc76:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc77:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc78:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc79:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc7:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc80:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc81:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc82:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc83:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc84:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc85:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc86:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc87:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc88:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc89:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc8:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc90:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc91:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc92:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc93:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc94:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc95:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc96:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc97:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc98:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc99:*:*:*:node.js:*:* cpe:2.3:a:monospace:directus:9.0.0:rc9:*:*:*:node.js:*:* |
|
| Vendors & Products |
Monospace
Monospace directus |
Thu, 27 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Mar 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the enumeration of unknown field contents. The searchable columns (numbers & strings) are not checked against permissions when injecting the `where` clauses for applying the search query. This leads to the possibility of enumerating those un-permitted fields. Version 11.5.0 fixes the issue. | |
| Title | Directus `search` query parameter allows enumeration of non permitted fields | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-27T15:15:07.652Z
Reserved: 2025-03-21T14:12:06.270Z
Link: CVE-2025-30352
Updated: 2025-03-27T15:15:00.582Z
Status : Analyzed
Published: 2025-03-26T18:15:27.080
Modified: 2025-08-26T01:41:50.303
Link: CVE-2025-30352
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:06:52Z
EUVD
Github GHSA