CVE-2024-31207

MEDIUM

NPM Vite < 2.9.18 - Information Disclosure

Title source: rule
STIX 2.1

Description

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18.

Scores

CVSS v3 5.9
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (7)
npm/vite 2.7.0 - 2.9.18npm
vitejs/vite >= 2.7.0, <= 2.9.17
vitejs/vite >= 3.0.0, <= 3.2.8
vitejs/vite >= 4.0.0, <= 4.5.2
vitejs/vite >= 5.0.0, <= 5.0.12
vitejs/vite >= 5.1.0, <= 5.1.6
vitejs/vite >= 5.2.0, <= 5.2.5
Published Apr 04, 2024
Tracked Since Feb 18, 2026