Описание
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, .crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.
A flaw was found in Vite, a frontend tooling framework for JavaScript. On the Vite development server, a remote attacker could exploit this vulnerability by appending specific query parameters, such as ?raw, to requests. This allows the attacker to bypass security restrictions and retrieve sensitive files, including environment variables (.env) and certificate files (.crt), which should otherwise be blocked. This information disclosure could lead to further compromise of the system.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Advanced Cluster Security 4 | rhacs-eng/release-main | Not affected | ||
| Red Hat Ansible Automation Platform 2 | automation-controller | Will not fix | ||
| Red Hat Ansible Automation Platform 2 | automation-eda-controller | Not affected | ||
| Red Hat Ansible Automation Platform 2 | automation-gateway | Not affected | ||
| Red Hat Ansible Automation Platform 2 | automation-platform-ui | Not affected | ||
| Red Hat Ansible Automation Platform 2 | redhat-user-workloads/gateway-rhel9 | Not affected | ||
| Red Hat Build of Keycloak | vite | Will not fix | ||
| Red Hat Build of Podman Desktop | podman-desktop-macos-1-0 | Affected | ||
| Red Hat Build of Podman Desktop | podman-desktop-windows-1-0 | Affected | ||
| Red Hat Build of Podman Desktop - Tech Preview | redhat-user-workloads/bootc-ext | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.
Vite is a frontend tooling framework for JavaScript. From 7.1.0 to bef ...
EPSS
7.5 High
CVSS3