PT-2022-22631 · Vitejs · Vite

Stypropened

·

Published

2022-08-18

·

Updated

2022-08-19

·

CVE-2022-35204

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vitejs Vite versions prior to 2.9.13
Description The issue allows attackers to perform a directory traversal via a crafted URL to the victim's service. This can be achieved by sending a specifically designed URL to the victim's service, potentially leading to unauthorized access to sensitive information.
Recommendations For versions prior to 2.9.13, update to version 2.9.13 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories and implementing additional security measures to prevent unauthorized access.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-35204
GHSA-MV48-HCVH-8JJ8

Affected Products

Vite