Description
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
Remediation
References
https://github.com/vitejs/vite/issues/8498
https://github.com/vitejs/vite/releases/tag/v2.9.13
https://github.com/vitejs/vite/releases/tag/v3.0.0-beta.4
Related Vulnerabilities
CVE-2021-40660 Vulnerability in maven package org.javadelight:delight-nashorn-sandbox
CVE-2020-7656 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2022-36127 Vulnerability in npm package skywalking-backend-js
CVE-2021-39148 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-40572 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore