CVE-2025-30350
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2025-30350 affects Directus, a real-time API and App dashboard for managing SQL database content, where the `@directus/storage-driver-s3` package, starting from version 9.22.0 and up to 12.0.0, is vulnerable. This issue arises due to asset unavailability after a burst of HEAD requests, causing all assets to be served as 403, resulting in asset denial for all Directus policies, including Admin and Public. Tools that rely on Directus to sync content and assets, particularly those utilizing the HEAD method to check file existence, are susceptible to this vulnerability. The issue is resolved in version 12.0.1 of the `@directus/storage-driver-s3` package, corresponding to Directus version 11.5.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.