7.1.10
5 years ago
1 days ago
Known vulnerabilities in the vite package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Relative Path Traversal via improper enforcement of Note:
This is only exploitable if the server is explicitly exposed to the network using the How to fix Relative Path Traversal? Upgrade | <5.4.20>=6.0.0 <6.3.6>=7.0.0 <7.0.7>=7.1.0 <7.1.5 |
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Directory Traversal through the Note: This is only exploitable if the application is explicitly exposing the Vite dev server to the network (using How to fix Directory Traversal? Upgrade | <4.5.14>=5.0.0 <5.4.19>=6.0.0 <6.1.6>=6.2.0 <6.2.7>=6.3.0 <6.3.4 |
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Information Exposure due to the handling of Note: This is only exploitable if the Vite dev server is explicitly exposed to the network and running on Node or Bun runtimes, excluding Deno. How to fix Information Exposure? Upgrade | <4.5.13>=5.0.0 <5.4.18>=6.0.0 <6.0.15>=6.1.0 <6.1.5>=6.2.0 <6.2.6 |
vite is a Native-ESM powered web dev build tool Affected versions of this package are vulnerable to Incorrect Authorization via the bypass of the Note: This is only exploitable if the file is smaller than the How to fix Incorrect Authorization? Upgrade | <4.5.12>=5.0.0 <5.4.17>=6.0.0 <6.0.14>=6.1.0 <6.1.4>=6.2.0 <6.2.5 |