Executive brief
rollup-plugin-server is a development tool that serves bundled JavaScript applications during development. A directory traversal vulnerability in its file serving function allows attackers over the network to read arbitrary files from the server's filesystem, potentially exposing sensitive configuration files, private keys, and source code without needing authentication.
Technical details
This is a path traversal vulnerability (CWE-22) in the readFileFromContentBase function, where user-supplied file paths are not sanitized before being used in file read operations. An attacker can craft requests using "../" sequences or absolute paths to escape the intended serving directory and access files anywhere on the filesystem. The vulnerability affects all versions up to 0.7.0, is remotely exploitable over the network, requires no authentication or user interaction, and results in information disclosure. No patched version has been released.
Affected products
- rollup-plugin-server rollup-plugin-server 0 through 0.7.0
Timeline
- 2020-06-20: disclosed
- 2020-07-29: advisory