Vite before v2.9.13 vulnerable to directory traversal via crafted URL to victim's service
High severity
GitHub Reviewed
Published
Aug 19, 2022
to the GitHub Advisory Database
•
Updated Sep 23, 2024
Package
Affected versions
< 2.9.13
>= 3.0.0-alpha.0, < 3.0.0-beta.4
Patched versions
2.9.13
3.0.0-beta.4
Description
Published by the National Vulnerability Database
Aug 18, 2022
Published to the GitHub Advisory Database
Aug 19, 2022
Reviewed
Aug 30, 2022
Last updated
Sep 23, 2024
Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
References