CVE-2023-34092

Source
https://cve.org/CVERecord?id=CVE-2023-34092
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34092.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-34092
Aliases
Published
2023-06-01T16:29:51.428Z
Modified
2026-08-12T03:51:34.678374898Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)
Details

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default fs.deny settings (['.env', '.env.*', '*.{crt,pem}']). Only users explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in vite@4.3.9, vite@4.2.3, vite@4.1.5, vite@4.0.5, vite@3.2.7, and vite@2.9.16.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-50"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34092.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/vitejs/vite

Affected ranges

Type
GIT
Repo
https://github.com/vitejs/vite
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:*",
        "cpe:2.3:a:vitejs:vite:2.9.15:*:*:*:*:node.js:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "3.0.2"
        },
        {
            "fixed": "3.2.7"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.0.5"
        },
        {
            "introduced": "4.1.0"
        },
        {
            "fixed": "4.1.5"
        },
        {
            "introduced": "4.2.0"
        },
        {
            "fixed": "4.2.3"
        },
        {
            "introduced": "4.3.0"
        },
        {
            "fixed": "4.3.9"
        },
        {
            "introduced": "2.9.15"
        },
        {
            "last_affected": "2.9.15"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.9.15
create-vite@3.*
create-vite@3.0.1
create-vite@3.0.2
create-vite@3.1.0
create-vite@3.2.0
create-vite@3.2.1
create-vite@4.*
create-vite@4.0.0
create-vite@4.1.0
create-vite@4.2.0
create-vite@4.3.0
create-vite@4.3.1
plugin-legacy@2.*
plugin-legacy@2.0.1
plugin-legacy@2.1.0
plugin-legacy@2.1.0-beta.0
plugin-legacy@2.2.0
plugin-legacy@2.3.0
plugin-legacy@2.3.0-beta.0
plugin-legacy@2.3.1
plugin-legacy@3.*
plugin-legacy@3.0.0
plugin-legacy@3.0.1
plugin-legacy@4.*
plugin-legacy@4.0.0
plugin-legacy@4.0.1
plugin-legacy@4.0.2
plugin-legacy@4.0.3
plugin-legacy@4.0.4
plugin-react@2.*
plugin-react@2.0.1
plugin-react@2.1.0
plugin-react@2.1.0-beta.0
plugin-react@2.2.0
plugin-react@2.2.0-beta.0
plugin-vue-jsx@2.*
plugin-vue-jsx@2.0.1
plugin-vue-jsx@2.1.0
plugin-vue-jsx@2.1.0-beta.0
plugin-vue-jsx@2.1.1
plugin-vue@3.*
plugin-vue@3.0.2
plugin-vue@3.0.3
plugin-vue@3.1.0
plugin-vue@3.1.0-beta.0
plugin-vue@3.2.0
plugin-vue@3.2.0-beta.0
v3.*
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.0-beta.0
v3.1.0-beta.1
v3.1.0-beta.2
v3.1.1
v3.1.2
v3.1.3
v3.2.0
v3.2.0-beta.0
v3.2.0-beta.1
v3.2.0-beta.2
v3.2.0-beta.3
v3.2.0-beta.4
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.0.4
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.2.0
v4.2.1
v4.2.2
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.3.6
v4.3.7
v4.3.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34092.json"