CVE-2025-30351
CVSS 3.1 Score 3.5 of 10 (low)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 672
Summary
CVE-2025-30351 is a vulnerability affecting Directus, a real-time API and App dashboard for managing SQL database content. In versions 10.10.0 and prior to 11.5.0, a suspended user can bypass access restrictions by using a token generated during session auth mode. This issue arises due to a missing check in `verifySessionJWT` that verifies if the user is still active and authorized to access the API. Consequently, a user can continue using the token until its expiration, even after being suspended. Directus resolved this vulnerability in version 11.5.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.