CVE-2024-23331 is a bypass vulnerability in the Vite frontend framework's development server, primarily affecting Windows systems due to their case-insensitive file systems. Attackers can bypass the server.fs.deny blacklist by requesting sensitive files with case-augmented filenames, leading to unauthorized information disclosure. This vulnerability has a CVSS score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity and no user interaction required, resulting in high confidentiality impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7.0, < 2.9.17CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 3.0.0, < 3.2.8CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 4.0.0, < 4.5.2CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* | ||
>= 5.0.0, < 5.0.12CPE matchmatch criteria | cpe:2.3:a:vitejs:vite:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.