Vulnerabilities/

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

Severity:
High

Description

Vite dev server option server.fs.deny can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows.

This bypass is similar to https://nvd.nist.gov/vuln/detail/CVE-2023-34092 – with surface area reduced to hosts having case-insensitive filesystems.

Recommendation

Update the vite package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
vite
Anything's wrong? Let us know Last updated on January 19, 2024

This issue is available in SmartScanner Professional

See Pricing