Asset Unavailability Vulnerability in Directus by Directus
CVE-2025-30225

5.3MEDIUM

Key Information:

Vendor

Directus

Status
Vendor
CVE Published:
26 March 2025

What is CVE-2025-30225?

The Directus platform encounters an asset unavailability issue when handling a surge of malformed transformation requests. In particular, the vulnerability exists in the '@directus/storage-driver-s3' package versions starting from 9.22.0 and before 12.0.1, as well as in the Directus versions from 9.22.0 to prior to 11.5.0. During high-demand scenarios, all assets may return a 403 status, resulting in denied access across all policies, including Admin and Public access. This flaw necessitates upgrading to version 12.0.1 of the storage driver and version 11.5.0 of Directus to mitigate the risk.

Affected Version(s)

directus >= 9.22.0, < 11.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.