Directory Traversal Vulnerability in Vite Frontend Build Tool
CVE-2024-31207

Currently unrated

Key Information:

Vendor

Vite

Status
Vendor
CVE Published:
4 April 2024

What is CVE-2024-31207?

A directory traversal vulnerability in the Vite frontend build tool allows attackers to bypass directory restrictions set by the server.fs.deny configuration. This flaw can lead to unauthorized access to files on the server, compromising the security of the application. It affects various versions of Vite, and users are strongly advised to update to the latest patched versions to mitigate risks.

References

Timeline

  • Vulnerability published

.
CVE-2024-31207 : Directory Traversal Vulnerability in Vite Frontend Build Tool