Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
Vulnerability threat dossier
Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue has been patched in versions 5.4.6, 5.3.6, 5.2.14, 4.5.5, and 3.2.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.
VTP analyst assessment
BleepingComputer reports mass scanning of internet-exposed Vite development servers to steal cloud credentials and configuration. CVE-2024-45811 lets a requester bypass Vite's @fs serving restriction with ?import&raw and return existing file contents.
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
BleepingComputer reports the campaign; the available record does not independently confirm its scale or specific victim impact.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
If you use Vite development servers, remove them from internet exposure and upgrade to 5.4.6, 5.3.6, 5.2.14, 4.5.5, or 3.2.11 or later.
VTP deterministic assessment
EPSS is 0.01; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
No material changes are recorded for this subject.
Claim provenance
0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.
Original publications
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.