Record summary

CVE-2024-31207 has a selected CVSS score of 5.9 (medium).

Description

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List>= 2.7.0, <= 2.9.17affected
>= 3.0.0, <= 3.2.8affected
>= 4.0.0, <= 4.5.2affected
>= 5.0.0, <= 5.0.12affected
>= 5.1.0, <= 5.1.6affected
>= 5.2.0, <= 5.2.5affected
GitHub Advisory2.7.0 to < 2.9.18 · Fixed in 2.9.18affected
3.0.0 to < 3.2.10 · Fixed in 3.2.10affected
4.0.0 to < 4.5.3 · Fixed in 4.5.3affected
5.0.0 to < 5.0.13 · Fixed in 5.0.13affected
5.1.0 to < 5.1.7 · Fixed in 5.1.7affected
5.2.0 to < 5.2.6 · Fixed in 5.2.6affected

References

9