Описание
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
A flaw was found in the Vite Node.js package. Vite exposes content of non-allowed files using ?inline&import
or ?raw?import
. Only apps explicitly exposing the Vite dev server to the network (using the --host
or server.host
config options) are affected.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Ansible Automation Platform 2 | automation-controller | Fix deferred | ||
Red Hat Ansible Automation Platform 2 | automation-eda-controller | Fix deferred | ||
Red Hat Ansible Automation Platform 2 | automation-gateway | Fix deferred | ||
Red Hat JBoss Enterprise Application Platform 8 | org.keycloak-keycloak-parent | Fix deferred | ||
Red Hat JBoss Enterprise Application Platform Expansion Pack | org.keycloak-keycloak-parent | Fix deferred | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-gateway-opa-rhel8 | Fix deferred | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-gateway-rhel8 | Fix deferred | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-jaeger-query-rhel8 | Fix deferred | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-query-rhel8 | Fix deferred | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and 4.5.11.
Vite is a frontend tooling framework for javascript. Vite exposes cont ...
Vite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
5.3 Medium
CVSS3