Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in [email protected], [email protected], [email protected], [email protected], [email protected], and [email protected].
We have discovered 378 live websites that are affected by CVE-2023-34092.
| Product | |
| Category | Dev Tools |
| Vulnerable Domains | 378 live websites (48% of Vite install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 31 versions ( 66% of all versions) |
| 149 websites | |
| 43 websites | |
| 36 websites | |
| 28 websites | |
| 21 websites | |
| 15 websites | |
| 8 websites | |
| 8 websites | |
| 7 websites | |
| 7 websites |
| .com | 163 websites |
| .cz | 40 websites |
| .de | 27 websites |
| .pl | 18 websites |
| .fr | 17 websites |
| .org | 11 websites |
| .it | 10 websites |
| .net | 7 websites |
| .ca | 6 websites |
| .com.au | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.link | *,*** | ||
| *********.ru | **,*** | ||
| ***.***.*****.ch | **,*** | ||
| ******.it | **,*** | ||
| ******.******.it | **,*** | ||
| ****.****.me | **,*** | ||
| ********.com | **,*** | ||
| **************.com | ***,*** | ||
| *****.ie | ***,*** | ||
| **********.********.com | ***,*** |
FAQ