CVE-2024-23331
Description
Vite is a frontend tooling framework for javascript. The Vite dev server option server.fs.deny can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. This bypass is similar to CVE-2023-34092 -- with surface area reduced to hosts having case-insensitive filesystems. Since picomatch defaults to case-sensitive glob matching, but the file server doesn't discriminate; a blacklist bypass is possible. By requesting raw filesystem paths using augmented casing, the matcher derived from config.server.fs.deny fails to block access to sensitive files. This issue has been addressed in [email protected], [email protected], [email protected], and [email protected]. Users are advised to upgrade. Users unable to upgrade should restrict access to dev servers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
vitenpm | >= 2.7.0, < 2.9.17 | 2.9.17 |
vitenpm | >= 3.0.0, < 3.2.8 | 3.2.8 |
vitenpm | >= 4.0.0, < 4.5.2 | 4.5.2 |
vitenpm | >= 5.0.0, < 5.0.12 | 5.0.12 |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/vitepkg:apk/wolfi/vitepkg:npm/vitepkg:rpm/opensuse/velociraptor&distro=openSUSE%20Tumbleweed
< 5.0.12-r0+ 3 more
- (no CPE)range: < 5.0.12-r0
- (no CPE)range: < 5.0.12-r0
- (no CPE)range: >= 2.7.0, < 2.9.17
- (no CPE)range: < 0.7.0.4.git142.862ef23-1.1
Patches
Vulnerability mechanics
References
9- github.com/vitejs/vite/commit/91641c4da0a011d4c5352e88fc68389d4e1289a5nvdPatchWEB
- github.com/vitejs/vite/security/advisories/GHSA-c24v-8rfc-w8vwnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-c24v-8rfc-w8vwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-34092ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23331ghsaADVISORY
- github.com/vitejs/vite/commit/0cd769c279724cf27934b1270fbdd45d68217691ghsaWEB
- github.com/vitejs/vite/commit/a26c87d20f9af306b5ce3ff1648be7fa5146c278ghsaWEB
- github.com/vitejs/vite/commit/eeec23bbc9d476c54a3a6d36e78455867185a7cbghsaWEB
- vitejs.dev/config/server-options.htmlnvdProductWEB
News mentions
0No linked articles in our index yet.