CVE-2023-34092

Vite Server Options (server.fs.deny) can be bypassed using double forward-slash (//)

Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings (`['.env', '.env.*', '*.{crt,pem}']`). Only users explicitly exposing the Vite dev server to the network (using `--host` or `server.host` config option) are affected, and only files in the immediate Vite project root folder could be exposed. This issue is fixed in [email protected], [email protected], [email protected], [email protected], [email protected], and [email protected].


We have discovered 378 live websites that are affected by CVE-2023-34092.

Run a Free Instant Scan




Affected Software

Product  Vite
Category Dev Tools
Vulnerable Domains378 live websites (48% of Vite install base)
Vulnerable Versions
  • from 0 through 2.9.16
  • from 3.0.2 through 3.2.7
  • from 4 through 4.0.5
  • from 4.1 through 4.1.5
  • from 4.2 through 4.2.3
  • from 4.3 through 4.3.9
Vulnerable Versions Count31 versions ( 66% of all versions)


Common Weakness Enumeration

CWE-50 Path Equivalence: '//multiple/leading/slash'



Details

  • Published - Jun 1, 2023
  • Updated - Jan 8, 2025

Website Distribution by Country

Number of websites using CVE-2023-34092
United States149 websites



Czech Republic43 websites
Germany36 websites
France28 websites
Poland21 websites
China15 websites
Canada8 websites
Netherlands8 websites
Vietnam7 websites
Mexico7 websites

Website Distribution by TLD

Number of websites using CVE-2023-34092
.com163 websites
.cz40 websites
.de27 websites
.pl18 websites
.fr17 websites
.org11 websites
.it10 websites
.net7 websites
.ca6 websites
.com.au5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-34092

Top websites that are affected by CVE-2023-34092. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.link Russia*,***
*********.ru Russia**,***
***.***.*****.ch United States**,***
******.it United States**,***
******.******.it **,***
****.****.me Japan**,***
********.com United States**,***
**************.com United States***,***
*****.ie Ireland***,***
**********.********.com United States***,***
See full domain list

FAQ

CVE-2023-34092 is Path Equivalence: '//multiple/leading/slash' in Vite
A total of 378 websites have been identified as vulnerable to CVE-2023-34092, based on global website indexing conducted by WebTechSurvey.
The Vite is affected by the CVE-2023-34092 vulnerability.
Vite versions up to 4.3.9 are vulnerable to CVE-2023-34092.
CVE-2023-34092 is resolved in version 4.3.9 of Vite.