Skip to content

chore(deps): update dependency vite to v5.4.6 [security] (stable29) - #6419

Merged
github-actions[bot] merged 1 commit into
stable29from
renovate/stable29-npm-vite-vulnerability
Sep 17, 2024
Merged

chore(deps): update dependency vite to v5.4.6 [security] (stable29)#6419
github-actions[bot] merged 1 commit into
stable29from
renovate/stable29-npm-vite-vulnerability

Conversation

@renovate

@renovaterenovateBot commented Sep 17, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeAdoptionPassingConfidence
vite (source)5.4.5 -> 5.4.6ageadoptionpassingconfidence

GitHub Vulnerability Alerts

CVE-2024-45811

Summary

The contents of arbitrary files can be returned to the browser.

Details

@fs denies access to files outside of Vite serving allow list. Adding ?import&raw to the URL bypasses this limitation and returns the file content if it exists.

PoC

$ npm create vite@latest
$ cd vite-project/
$ npm install
$ npm run dev
$ echo"top secret content"> /tmp/secret.txt
# expected behaviour
$ curl "http://localhost:5173/@&#8203;fs/tmp/secret.txt"<body><h1>403 Restricted</h1><p>The request url &quot;/tmp/secret.txt&quot; is outside of Vite serving allow list.
# security bypassed
$ curl "http://localhost:5173/@&#8203;fs/tmp/secret.txt?import&raw"export default "top secret content\n"
//# sourceMappingURL=data:application/json;base64,eyJ2...

Release Notes

vitejs/vite (vite)

v5.4.6

Compare Source

Please refer to CHANGELOG.md for details.


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovaterenovateBot added the dependencies Pull requests that update a dependency file label Sep 17, 2024
@github-actions
github-actionsBot merged commit 2f50664 into stable29Sep 17, 2024
@github-actions
github-actionsBot deleted the renovate/stable29-npm-vite-vulnerability branch September 17, 2024 20:16
@AltahrimAltahrim mentioned this pull request Oct 1, 2024
1 task
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants