CVE-2024-31207Sensitive Information Exposure in Vite

Severity
5.9MEDIUMNVD
EPSS
0.2%
top 60.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 4

Description

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

npmvitejs/vite2.7.02.9.18+5
CVEListV5vitejs/vite6 versions+5

🔴Vulnerability Details

2
OSV
Vite's `server.fs.deny` did not deny requests for patterns with directories.2024-04-03
GHSA
Vite's `server.fs.deny` did not deny requests for patterns with directories.2024-04-03

📋Vendor Advisories

1
Red Hat
vitejs: "server.fs.deny" configuration does not deny requests that include patterns2024-04-04