github.com
https://github.com/vitejs/vite CVE-2024-45811
server.fs.deny bypassed when using ?import&raw in vite
Description
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 5.4.0 to < 5.4.6 | affected |
| 5.3.0 to < 5.3.6 | affected | ||
| 5.0.0 to < 5.2.14 | affected | ||
| 4.0.0 to < 4.5.5 | affected | ||
| Before 3.2.11 | affected | ||
| >= 5.4.0, < 5.4.6 | affected | ||
| >= 5.3.0, < 5.3.6 | affected | ||
| >= 5.0.0, < 5.2.14 | affected | ||
| >= 4.0.0, < 4.5.5 | affected | ||
| < 3.2.11 | affected | ||
| GitHub Advisory | 5.4.0 to < 5.4.6 · Fixed in 5.4.6 | affected | |
| 5.3.0 to < 5.3.6 · Fixed in 5.3.6 | affected | ||
| 5.2.0 to < 5.2.14 · Fixed in 5.2.14 | affected | ||
| 4.0.0 to < 4.5.4 · Fixed in 4.5.4 | affected | ||
| Before 3.2.11 · Fixed in 3.2.11 | affected | ||
| 5.0.0 to < 5.1.8 · Fixed in 5.1.8 | affected |
References
8github.com
https://github.com/vitejs/vite/commit/4573a6fd6f1b097fb7296a3e135e0646b996b249 github.com
https://github.com/vitejs/vite/commit/6820bb3b9a54334f3268fc5ee1e967d2e1c0db34 github.com
https://github.com/vitejs/vite/commit/8339d7408668686bae56eaccbfdc7b87612904bd github.com
https://github.com/vitejs/vite/commit/a6da45082b6e73ddfdcdcc06bb5414f976a388d6 github.com
https://github.com/vitejs/vite/commit/b901438f99e667f76662840826eec91c8ab3b3e7 github.comConfirmation
https://github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45811