Description

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List5.4.0 to < 5.4.6affected
5.3.0 to < 5.3.6affected
5.0.0 to < 5.2.14affected
4.0.0 to < 4.5.5affected
Before 3.2.11affected
>= 5.4.0, < 5.4.6affected
>= 5.3.0, < 5.3.6affected
>= 5.0.0, < 5.2.14affected
>= 4.0.0, < 4.5.5affected
< 3.2.11affected
GitHub Advisory5.4.0 to < 5.4.6 · Fixed in 5.4.6affected
5.3.0 to < 5.3.6 · Fixed in 5.3.6affected
5.2.0 to < 5.2.14 · Fixed in 5.2.14affected
4.0.0 to < 4.5.4 · Fixed in 4.5.4affected
Before 3.2.11 · Fixed in 3.2.11affected
5.0.0 to < 5.1.8 · Fixed in 5.1.8affected

References

8