Junglewise Threat Intelligence

CVE-2024-47068: rollup DOM Clobbering gadget leading to XSS

CVE-2024-47068 · Severity: low · CVSS 3.1 · Published 2024-09-23

Executive brief

Rollup is a popular JavaScript module bundler used to package web applications. When bundling scripts that use import.meta with cjs, umd, or iife output formats, rollup generates code vulnerable to DOM Clobbering attacks. An attacker can inject harmless-looking HTML elements (like image tags) that trick the bundled script into loading malicious JavaScript from a controlled server, enabling cross-site scripting attacks on web pages that contain both the bundled script and user-supplied HTML.

Technical details

This is a DOM Clobbering vulnerability in rollup's MetaProperty code generation. When bundling code containing import.meta.url, rollup replaces meta properties with lookups to document.currentScript without type checking. An attacker can shadow document.currentScript through the browser's named element access mechanism by injecting an HTML element (e.g., <img name="currentScript">) with a malicious src attribute. The generated bundle then uses the attacker's src value as the URL for dynamically loading scripts, enabling XSS. The vulnerability affects rollup versions ≥0.59.0 <2.79.2, ≥3.0.0 <3.29.5, and ≥4.0.0 <4.22.4. Patches are available in versions 2.79.2, 3.29.5, and 4.22.4, which add type checking (tagName === 'SCRIPT') to prevent clobbering.

Affected products

  • rollup rollup >=0.59.0 <2.79.2, >=3.0.0 <3.29.5, >=4.0.0 <4.22.4

Timeline

  • 2024-09-23: disclosed
  • 2024-09-21: patched: Patches released in versions 2.79.2, 3.29.5, and 4.22.4

References