Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot Alert: Vite's server.fs.deny is bypassed when using ?import&raw #651

Open
JennaySDavis opened this issue Sep 18, 2024 · 2 comments

Comments

@JennaySDavis
Copy link
Contributor

The contents of arbitrary files can be returned to the browser.

@JennaySDavis
Copy link
Contributor Author

651 Acceptance Criteria

Pass/Fail Description
Pass Full Regression Testing of Training Website

Comments/Additional Notes
N/A

ADA Compliance (Automated scan via Chrome Lighthouse)

Criteria Score
Performance 100
Accessibility 100
Best Practices 100

Passed 10/16/2024 - JSD

@johnbeallgsa
Copy link

Thanks for explaining in the demo. I am moving to Done.

felder101 added a commit that referenced this issue Oct 17, 2024
Dependabot Alert: Vite's server.fs.deny is bypassed when using ?import&raw #651
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Biobased in Training #663
felder101 added a commit that referenced this issue Oct 18, 2024
Dependabot Alert: Vite's server.fs.deny is bypassed when using ?import&raw #651
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Dependabot Alert: Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS #650
Biobased in Training #663
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants