CVE-2022-35204: Path Traversal
Published Aug 18, 2022
·Updated
Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
Affected Software
3 affected componentsFixes available
npm/vite>=3.0.0-alpha.0<3.0.0-beta.4
3.0.0-beta.4
npm/vite<2.9.13
2.9.13
vitejs Vite Node.js<2.9.13
Remediation
Patch Available
Event History
Aug 18, 2022
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
Description
Aug 19, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2022-35204?
CVE-2022-35204 is a vulnerability in Vitejs Vite before version 2.9.13 that allows attackers to perform directory traversal attacks.
2
How severe is CVE-2022-35204?
CVE-2022-35204 has a severity level of medium with a CVSS score of 4.3.
3
How can I fix CVE-2022-35204?
To fix CVE-2022-35204, update Vitejs Vite to version 2.9.13 or later.
4
What is directory traversal?
Directory traversal is a vulnerability that allows an attacker to access files and directories outside of the intended scope.
5
Where can I find more information about CVE-2022-35204?
You can find more information about CVE-2022-35204 on the Vitejs Vite GitHub page and the associated release notes.