Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1159 | Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18. |
Github GHSA |
GHSA-8jhw-289h-jh2g | Vite's `server.fs.deny` did not deny requests for patterns with directories. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:46:04.483Z
Reserved: 2024-03-29T14:16:31.900Z
Link: CVE-2024-31207
Updated: 2024-05-23T19:01:22.140Z
Status : Awaiting Analysis
Published: 2024-04-04T16:15:09.333
Modified: 2024-11-21T09:13:02.403
Link: CVE-2024-31207
OpenCVE Enrichment
Updated: 2025-07-13T11:32:06Z
EUVD
Github GHSA