Vite是Vite开源的一种新型的前端构建工具。 Vite 2.9.16版本、3.2.7版本、4.0.5版本、4.1.5版本、4.2.3版本、4.3.9版本存在安全漏洞。攻击者利用该漏洞从应用程序的Vite根路径读取文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | test-cve-2023-34092 | https://github.com/FlapyPan/test-cve-2023-34092 | POC Details |
| 2 | Vite dev server could allow reading files from the Vite project root by bypassing server.fs.deny with double forward-slash paths (//). This affects exposed dev servers only. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-34092.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet