Junglewise Threat Intelligence

CVE-2024-45811: Vite server.fs.deny bypass via ?import&raw query parameter

CVE-2024-45811 · Severity: low · CVSS 3.1 · Published 2024-09-17

Technologies: Vite. Vendors: Vite.

Executive brief

Vite is a popular front-end build tool that includes security controls to restrict which files developers can access during local development. An attacker can bypass these file access restrictions by appending `?import&raw` to a URL, allowing unauthorized reading of sensitive files stored on the development server's filesystem. This could expose secrets, configuration files, or other sensitive data to anyone with network access to the development server.

Technical details

The vulnerability is a file access control bypass (CWE-200, CWE-284) affecting Vite's `server.fs.deny` security mechanism. The `@fs` endpoint correctly denies access to files outside the configured allow list; however, appending the `?import&raw` query parameter to such requests bypasses this check and returns the file content as JavaScript. The vulnerability is present in Vite versions 4.0.0–5.4.5 across multiple release branches. No authentication or special privileges are required; the attack is network-accessible. Patches are available in versions 3.2.11, 4.5.4, 5.1.8, 5.2.14, 5.3.6, and 5.4.6.

Affected products

  • Vite Vite 4.0.0–4.5.3, 5.0.0–5.4.5, and all versions prior to 3.2.11

Timeline

  • 2024-09-17: disclosed
  • 2024-09-17: patched

References

Related threats