Vitejs

Vite

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 17.09.2024 20:15:05
  • Zuletzt bearbeitet 20.09.2024 12:30:51

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses thi...

  • EPSS 0.14%
  • Veröffentlicht 04.04.2024 16:15:09
  • Zuletzt bearbeitet 21.11.2024 09:13:02

Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in ver...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 19.01.2024 20:15:14
  • Zuletzt bearbeitet 21.11.2024 08:57:31

Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. This bypass ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 04.12.2023 23:15:27
  • Zuletzt bearbeitet 21.11.2024 08:33:12

Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`<script typ...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 01.06.2023 17:15:10
  • Zuletzt bearbeitet 21.11.2024 08:06:31

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-pa...

Exploit
  • EPSS 1.18%
  • Veröffentlicht 18.08.2022 19:15:14
  • Zuletzt bearbeitet 21.11.2024 07:10:53

Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.