[Security] Bump rollup from 2.79.1 to 3.29.5
Bumps rollup from 2.79.1 to 3.29.5. This update includes a security fix.
Vulnerabilities fixed
DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
Summary
A DOM Clobbering vulnerability was discovered in rollup when bundling scripts that use
import.meta.url
or with plugins that emit and reference asset files from code incjs
/umd
/iife
format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., animg
tag with an unsanitizedname
attribute) are present.It's worth noting that similar issues in other popular bundlers like Webpack (CVE-2024-43788) have been reported, which might serve as a good reference.
Details
Backgrounds
DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. More for information about DOM Clobbering, here are some references:
[1] https://scnps.co/papers/sp23_domclob.pdf [2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/
Gadget found in
rollup
A DOM Clobbering vulnerability in
rollup
bundled scripts was identified, particularly when the scripts usesimport.meta
and set output in format ofcjs
/umd
/iife
. In such cases,rollup
replaces meta property with the URL retrieved fromdocument.currentScript
.
... (truncated)
Patched versions: 4.22.4; 3.29.5 Affected versions: >= 4.0.0, < 4.22.4; < 3.29.5
Release notes
Sourced from rollup's releases.
v3.29.4
3.29.4
2023-09-28
Bug Fixes
- Fix static analysis when an exported function uses callbacks (#5158)
Pull Requests
- #5158: Deoptimize all parameters when losing track of a function (
@lukastaegert
)v3.29.3
3.29.3
2023-09-24
Bug Fixes
- Fix a bug where code was wrongly tree-shaken after mutating function parameters (#5153)
Pull Requests
- #5145: docs: improve the docs repl appearance in the light mode (
@TrickyPi
)- #5148: chore(deps): update dependency
@vue/eslint-config-typescript
to v12 (@renovate
[bot])- #5149: chore(deps): lock file maintenance minor/patch updates (
@renovate
[bot])- #5153: Fully deoptimize first level path when deoptimizing nested parameter paths (
@lukastaegert
)v3.29.2
3.29.2
2023-09-15
Bug Fixes
- Export
TreeshakingPreset
type (#5131)Pull Requests
- #5131: fix: exports
TreeshakingPreset
(@moltar
)- #5134: docs: steps to enable symlinks on windows (
@thebanjomatic
)- #5137: chore(deps): lock file maintenance minor/patch updates (
@renovate
[bot])v3.29.1
3.29.1
2023-09-10
Bug Fixes
... (truncated)
Changelog
Sourced from rollup's changelog.
rollup changelog
4.22.4
2024-09-21
Bug Fixes
- Fix a vulnerability in generated code that affects IIFE, UMD and CJS bundles when run in a browser context (#5671)
Pull Requests
- #5670: refactor: Use object.prototype to check for reserved properties (
@YuHyeonWook
)- #5671: Fix DOM Clobbering CVE (
@lukastaegert
)4.22.3
2024-09-21
Bug Fixes
- Ensure that mutations in modules without side effects are observed while properly handling transitive dependencies (#5669)
Pull Requests
- #5669: Ensure impure dependencies of pure modules are added (
@lukastaegert
)4.22.2
2024-09-20
Bug Fixes
- Revert fix for side effect free modules until other issues are investigated (#5667)
Pull Requests
- #5667: Partially revert #5658 and re-apply #5644 (
@lukastaegert
)4.22.1
2024-09-20
Bug Fixes
- Revert #5644 "stable chunk hashes" while issues are being investigated
Pull Requests
- #5663: chore(deps): update dependency inquirer to v11 (
@renovate
[bot],@lukastaegert
)
... (truncated)
Commits
-
dfd233d
3.29.5 -
2ef77c0
Fix DOM Clobbering CVE -
a6448b9
3.29.4 -
4e92d60
Deoptimize all parameters when losing track of a function (#5158) -
801ffd1
3.29.3 -
353e462
Fully deoptimize first level path when deoptimizing nested parameter paths (#... -
a1a89e7
chore(deps): update dependency@vue/eslint-config-typescript
to v12 (#5148) -
cc14f70
chore(deps): lock file maintenance minor/patch updates (#5149) -
1e8355b
docs: improve the docs repl appearance in the light mode (#5145) -
5950fc8
Adapt branches in REPL workflow - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts