generated from NethServer/ns8-kickstart
-
Notifications
You must be signed in to change notification settings - Fork 8
chore(deps): update dependency rollup to v2 [security] #506
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
main
Choose a base branch
from
renovate-npm-rollup-vulnerability
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+1
−1
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
a60ad12
to
1c08d76
Compare
1c08d76
to
888f95a
Compare
888f95a
to
4d9dfd0
Compare
4d9dfd0
to
dcee318
Compare
dcee318
to
be45224
Compare
be45224
to
76aa6c2
Compare
76aa6c2
to
516132a
Compare
516132a
to
dc5fd9f
Compare
dc5fd9f
to
169a8f1
Compare
169a8f1
to
ba5b7f5
Compare
ba5b7f5
to
f276a30
Compare
f276a30
to
142462b
Compare
142462b
to
80cd95c
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.23.1
->^2.79.2
GitHub Vulnerability Alerts
CVE-2024-47068
Summary
We discovered a DOM Clobbering vulnerability in rollup when bundling scripts that use
import.meta.url
or with plugins that emit and reference asset files from code incjs
/umd
/iife
format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., animg
tag with an unsanitizedname
attribute) are present.It's worth noting that we’ve identifed similar issues in other popular bundlers like Webpack (CVE-2024-43788), which might serve as a good reference.
Details
Backgrounds
DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. More for information about DOM Clobbering, here are some references:
[1] https://scnps.co/papers/sp23_domclob.pdf
[2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/
Gadget found in
rollup
We have identified a DOM Clobbering vulnerability in
rollup
bundled scripts, particularly when the scripts usesimport.meta
and set output in format ofcjs
/umd
/iife
. In such cases,rollup
replaces meta property with the URL retrieved fromdocument.currentScript
.https://github.com/rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts#L157-L162
https://github.com/rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts#L180-L185
However, this implementation is vulnerable to a DOM Clobbering attack. The
document.currentScript
lookup can be shadowed by an attacker via the browser's named DOM tree element access mechanism. This manipulation allows an attacker to replace the intended script element with a malicious HTML element. When this happens, thesrc
attribute of the attacker-controlled element (e.g., animg
tag ) is used as the URL for importing scripts, potentially leading to the dynamic loading of scripts from an attacker-controlled server.PoC
Considering a website that contains the following
main.js
script, the devloper decides to use therollup
to bundle up the program:rollup main.js --format cjs --file bundle.js
.The output
bundle.js
is shown in the following code snippet.Adding the
rollup
bundled script,bundle.js
, as part of the web page source code, the page could load theextra.js
file from the attacker's domain,attacker.controlled.server
due to the introduced gadget during bundling. The attacker only needs to insert animg
tag with the name attribute set tocurrentScript
. This can be done through a website's feature that allows users to embed certain script-less HTML (e.g., markdown renderers, web email clients, forums) or via an HTML injection vulnerability in third-party JavaScript loaded on the page.Impact
This vulnerability can result in cross-site scripting (XSS) attacks on websites that include rollup-bundled files (configured with an output format of
cjs
,iife
, orumd
and useimport.meta
) and allow users to inject certain scriptless HTML tags without properly sanitizing thename
orid
attributes.Patch
Patching the following two functions with type checking would be effective mitigations against DOM Clobbering attack.
Release Notes
rollup/rollup (rollup)
v2.79.2
Compare Source
2024-09-26
Bug Fixes
Pull Requests
v2.79.1
Compare Source
2022-09-22
Bug Fixes
Pull Requests
v2.79.0
Compare Source
2022-08-31
Features
amd.forceJsExtensionForImports
to enforce using.js
extensions for relative AMD imports (#4607)Pull Requests
v2.78.1
Compare Source
2022-08-19
Bug Fixes
Pull Requests
v2.78.0
Compare Source
2022-08-14
Features
Pull Requests
v2.77.3
Compare Source
2022-08-11
Bug Fixes
Pull Requests
v2.77.2
Compare Source
2022-07-27
Bug Fixes
Pull Requests
v2.77.1
Compare Source
2022-07-26
Bug Fixes
Pull Requests
v2.77.0
Compare Source
2022-07-15
Features
maxParallelFileOps
to limit both read and write operations, default to 20 and replacesmaxParallelFileRead
(#4570)Bug Fixes
Pull Requests
v2.76.0
Compare Source
2022-07-08
Features
sourcmapBaseUrl
for absolute paths in sourcemaps (#4527)Bug Fixes
Pull Requests
v2.75.7
Compare Source
2022-06-20
Bug Fixes
Pull Requests
v2.75.6
Compare Source
2022-06-07
Bug Fixes
Pull Requests
v2.75.5
Compare Source
2022-06-01
Bug Fixes
Pull Requests
v2.75.4
Compare Source
2022-05-31
Bug Fixes
Pull Requests
v2.75.3
Compare Source
2022-05-29
Bug Fixes
Pull Requests
v2.75.2
Compare Source
v2.75.1
Compare Source
2022-05-28
Pull Requests
v2.75.0
Compare Source
2022-05-27
Features
.trim()
on template literals a side effect (#4511)Pull Requests
v2.74.1
Compare Source
2022-05-19
Bug Fixes
v2.74.0
Compare Source
2022-05-19
Features
Bug Fixes
Pull Requests
v2.73.0
Compare Source
2022-05-13
Features
Bug Fixes
Pull Requests
v2.72.1
Compare Source
2022-05-07
Bug Fixes
Pull Requests
v2.72.0
Compare Source
2022-05-05
Features
Bug Fixes
Pull Requests
v2.71.1
Compare Source
2022-04-30
Bug Fixes
Pull Requests
v2.71.0
Compare Source
2022-04-30
v2.70.2
Compare Source
2022-04-15
Bug Fixes
Pull Requests
v2.70.1
Compare Source
2022-03-14
Bug Fixes
Pull Requests
v2.70.0
Compare Source
2022-03-07
Features
watchChange
andcloseWatcher
hooks asynchronous and make Rollup wait for these hooks before continuing ( #4427)Bug Fixes
watchChange
but display them properly (#4427)Pull Requests
v2.69.2
Compare Source
2022-03-06
Bug Fixes
Object.entries
andObject.fromEntries
as pure (#4429)Pull Requests
v2.69.1
Compare Source
2022-03-04
Bug Fixes
Pull Requests
v2.69.0
Compare Source
2022-03-02
Features
output.generatedCode.symbols
to control the usage of Symbols in Rollup-generated code (#4378)output.namespaceToStringTag
in favor ofoutput.generatedCode.symbols
(#4378)Bug Fixes
./
and../
as external dependencies (#4419)Pull Requests
v2.68.0
Compare Source
2022-02-22
Features
shouldTransformCachedModule
(#4414)Pull Requests
v2.67.3
Compare Source
2022-02-18
Bug Fixes
Pull Requests
v2.67.2
Compare Source
2022-02-10
Bug Fixes
Pull Requests
v2.67.1
Compare Source
2022-02-07
Bug Fixes
Pull Requests
v2.67.0
Compare Source
2022-02-02
Features
moduleSideEffects
at any time during the build (#4379)ModuleInfo.hasModuleSideEffects
in favour ofModuleInfo.moduleSideEffects
(#4379)Bug Fixes
Pull Requests
v2.66.1
Compare Source
2022-01-25
Bug Fixes
Pull Requests
v2.66.0
Compare Source
2022-01-22
Features
this.load
(#4358)Pull Requests
v2.65.0
Compare Source
2022-01-21
Features
this.load
(#4354)Bug Fixes
perf: true
(#4357)Pull Requests
v2.64.0
Compare Source
2022-01-14
Features
Bug Fixes
meta
from the resolveId hook (#4347)Pull Requests
v2.63.0
Compare Source
2022-01-04
Features
this.load
(#4320)Bug Fixes
--watch
is missing (#4335)Pull Requests
v2.62.0
Compare Source
2021-12-24
Features
Bug Fixes
Pull Requests
v2.61.1
Compare Source
2021-12-11
Bug Fixes
Pull Requests
v2.61.0
Compare Source
2021-12-09
Features
Bug Fixes
Pull Requests
v2.60.2
Compare Source
2021-11-30
Bug Fixes
Pull Requests
v2.60.1
Compare Source
2021-11-22
Bug Fixes
Pull Requests
v2.60.0
Compare Source
2021-11-11
Features
this.load
context function to load, transform and parse modules without adding them to the graph (#4234)Pull Requests
v2.59.0
Compare Source
2021-11-01
Features
Bug Fixes
Pull Requests
v2.58.3
Compare Source
2021-10-25
Bug Fixes
v2.58.2
Compare Source
2021-10-25
Bug Fixes
v2.58.1
Compare Source
2021-10-25
Bug Fixes
Pull Requests
v2.58.0
Compare Source
2021-10-01
Features
resolveId
hook (#4230)Pull Requests
v2.57.0
Compare Source
2021-09-22
Features
generatedCode
option to allow Rollup to use es2015 features for smaller output and more efficient helpers ( #4215)preferConst
will now show a warning withstrictDeprecations: true
(#4215)Bug Fixes
Object.assign
in generated code to ensConfiguration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.