Vulnerabilities/

Directus's S3 assets become unavailable after a burst of HEAD requests

Severity:
Medium

Description

There’s some tools that use Directus to sync content and assets. Some of those tools use HEAD method, like Shopify, to check the existence of files. Although, when making many HEAD requests at once, at some point, all assets are being served as 403.

Recommendation

Update the @directus/storage-driver-s3 package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@directus/storage-driver-s3
Anything's wrong? Let us know Last updated on March 27, 2025