← voltar
CVE-2024-45811mediumexploração observadaCWE-200CWE-284

server.fs.deny bypassed when using ?import&raw in vite

35Vexday Risk Score

Priorize a correção. Ela exploração observada pelo VulnCheck.

ssvc Attendcvss 4.8epss 1.1%
da publicação à arma
Publicada no NVD17 de set.
VulnCheck+724d
probabilidade de exploração
1.1%top 37% das CVEs
exploração observada
simVulnCheck
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Produtos afetados
vitejs · vite