CVE-2024-45811 PUBLISHED CVSS 4.800000190734863 MEDIUM

Vite's `server.fs.deny` is bypassed when using `?import&raw`

EPSS 0.02% · 2.9th percentile

Risk Scores

CVSS v3.1
4.800000190734863
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.02%
2.9th percentile

Affected Products

VendorProductVersions
npmvite5.2.0, 5.3.0, 5.4.0
vitejsvite0, 5.4.0, 5.3.0
vitejsvite>= 5.4.0, < 5.4.6, < 3.2.11, >= 4.0.0, < 4.5.5

Timeline

References

Open in Interactive Console →