Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-30208

Опубликовано: 24 мар. 2025
Источник: redhat
CVSS3: 5.3
EPSS Высокий

Описание

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. @fs denies access to files outside of Vite serving allow list. Adding ?raw?? or ?import&raw?? to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as ? are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

A flaw was found in the Vite frontend library. A remote attacker may be able to access files outside of the Vite serving allow list by entering specially-crafted query strings in the URL. This can allow for the contents of arbitrary files to be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2automation-controllerOut of support scope
Red Hat Ansible Automation Platform 2automation-eda-controllerNot affected
Red Hat Ansible Automation Platform 2automation-gatewayOut of support scope
Red Hat JBoss Enterprise Application Platform 8org.keycloak-keycloak-parentNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.keycloak-keycloak-parentNot affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-opa-rhel8Out of support scope
Red Hat OpenShift distributed tracing 3rhosdt/tempo-gateway-rhel8Out of support scope
Red Hat OpenShift distributed tracing 3rhosdt/tempo-jaeger-query-rhel8Out of support scope
Red Hat OpenShift distributed tracing 3rhosdt/tempo-query-rhel8Affected
Red Hat OpenShift distributed tracing 3rhosdt/tempo-rhel8Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-41
https://bugzilla.redhat.com/show_bug.cgi?id=2354598vite: Vite bypasses server.fs.deny when using `?raw??`

EPSS

Процентиль: 99%
0.74998
Высокий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This bypass exists because trailing separators such as `?` are removed in several places, but are not accounted for in query string regexes. The contents of arbitrary files can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected. Versions 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10 fix the issue.

CVSS3: 5.3
debian
больше 1 года назад

Vite, a provider of frontend development tooling, has a vulnerability ...

CVSS3: 5.3
github
больше 1 года назад

Vite bypasses server.fs.deny when using ?raw??

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость функции transformMiddleware механизма @fs локального сервера разработки приложений Vite, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 99%
0.74998
Высокий

5.3 Medium

CVSS3

Уязвимость CVE-2025-30208