CVE-2024-47068

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47068
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47068.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47068
Aliases
Related
Published
2024-09-23T16:15:06Z
Modified
2024-09-30T18:48:51.700706Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Rollup is a module bundler for JavaScript. Versions prior to 3.29.5 and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from import.meta (e.g., import.meta.url) in cjs/umd/iife format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present. Versions 3.29.5 and 4.22.4 contain a patch for the vulnerability.

References

Affected packages

Debian:11 / node-rollup

Package

Name
node-rollup
Purl
pkg:deb/debian/node-rollup?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.38.4-1
2.40.0-1
2.41.2-1
2.41.5-1
2.42.1-1
2.42.1-2
2.61.1-1
2.61.1-2
2.61.1-3
2.61.1-4
2.61.1-5
2.61.1-6
2.70.2-1
2.70.2-2
2.71.1-1
2.71.1-2
2.72.1-1
2.73.0-1
2.74.1-1
2.75.3-1
2.75.5-1
2.75.6-1
2.75.7-1
2.76.0-1
2.77.0-1
2.77.2-1
2.78.0-1
2.78.1-1
2.79.0-1
2.79.1-1

3.*

3.0.0~beta~8-1
3.2.3-1
3.2.5-1
3.2.5-2
3.3.0~beta~0-1
3.3.0-1
3.4.0-1
3.7.0-1
3.7.2-1
3.7.3-1
3.7.5-1
3.10.0-1
3.12.0-1
3.15.0-1
3.15.0-2
3.28.0-1
3.28.0-2
3.29.4-1
3.29.4-2
3.29.4-3
3.29.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / node-rollup

Package

Name
node-rollup
Purl
pkg:deb/debian/node-rollup?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.15.0-1
3.15.0-2
3.28.0-1
3.28.0-2
3.29.4-1
3.29.4-2
3.29.4-3
3.29.5-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / node-rollup

Package

Name
node-rollup
Purl
pkg:deb/debian/node-rollup?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.29.5-1

Affected versions

3.*

3.15.0-1
3.15.0-2
3.28.0-1
3.28.0-2
3.29.4-1
3.29.4-2
3.29.4-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/rollup/rollup

Affected ranges

Type
GIT
Repo
https://github.com/rollup/rollup
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v0.*

v0.10.0
v0.11.0
v0.11.1
v0.11.2
v0.11.4
v0.12.0
v0.12.1
v0.13.0
v0.14.0
v0.14.1
v0.15.0
v0.16.1
v0.16.2
v0.16.3
v0.16.4
v0.18.0
v0.18.2
v0.18.3
v0.18.4
v0.18.5
v0.19.0
v0.19.1
v0.19.2
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.20.5
v0.21.1
v0.21.2
v0.21.3
v0.22.0
v0.22.1
v0.22.2
v0.23.0
v0.23.1
v0.23.2
v0.24.0
v0.24.1
v0.25.1
v0.25.2
v0.25.3
v0.25.4
v0.25.7
v0.25.8
v0.26.0
v0.26.1
v0.26.2
v0.26.3
v0.26.4
v0.26.5
v0.26.6
v0.26.7
v0.27.0
v0.27.1
v0.28.0
v0.29.0
v0.29.1
v0.3.1
v0.30.0
v0.31.0
v0.31.1
v0.31.2
v0.32.0
v0.32.1
v0.32.2
v0.32.3
v0.32.4
v0.33.0
v0.33.1
v0.33.2
v0.34.0
v0.34.1
v0.34.10
v0.34.11
v0.34.12
v0.34.13
v0.34.2
v0.34.4
v0.34.5
v0.34.7
v0.34.8
v0.34.9
v0.35.0
v0.35.1
v0.35.10
v0.35.11
v0.35.12
v0.35.13
v0.35.14
v0.35.15
v0.35.2
v0.35.3
v0.35.4
v0.35.5
v0.35.6
v0.35.7
v0.35.8
v0.35.9
v0.36.0
v0.36.1
v0.36.2
v0.36.3
v0.36.4
v0.37.0
v0.37.1
v0.37.2
v0.38.0
v0.38.1
v0.38.2
v0.38.3
v0.39.0
v0.39.1
v0.39.2
v0.4.0
v0.4.1
v0.40.0
v0.40.1
v0.40.2
v0.41.0
v0.41.1
v0.41.2
v0.41.3
v0.41.4
v0.41.5
v0.41.6
v0.42.0
v0.43.0
v0.43.1
v0.44.0
v0.45.0
v0.45.1
v0.45.2
v0.46.0
v0.46.1
v0.46.2
v0.46.3
v0.47.0
v0.47.1
v0.47.2
v0.47.3
v0.47.4
v0.47.5
v0.47.6
v0.48.0
v0.48.1
v0.48.2
v0.49.0
v0.49.1
v0.49.2
v0.49.3
v0.5.0
v0.50.0
v0.50.1
v0.51.0
v0.51.1
v0.51.2
v0.51.3
v0.51.4
v0.51.5
v0.51.6
v0.51.7
v0.51.8
v0.52.0
v0.52.1
v0.52.2
v0.52.3
v0.53.0
v0.53.1
v0.53.2
v0.53.3
v0.53.4
v0.54.0
v0.54.1
v0.55.0
v0.55.1
v0.55.2
v0.55.3
v0.55.5
v0.56.0
v0.56.1
v0.56.2
v0.56.3
v0.56.4
v0.56.5
v0.57.0
v0.57.1
v0.58.0
v0.58.1
v0.58.2
v0.59.0
v0.59.1
v0.59.2
v0.59.3
v0.59.4
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.60.0
v0.60.1
v0.60.2
v0.60.3
v0.60.4
v0.60.5
v0.60.6
v0.60.7
v0.61.0
v0.61.1
v0.61.2
v0.62.0
v0.63.0
v0.63.1
v0.63.2
v0.63.3
v0.63.4
v0.63.5
v0.64.0
v0.64.1
v0.65.1
v0.65.2
v0.66.0
v0.66.1
v0.66.2
v0.66.3
v0.66.4
v0.66.5
v0.66.6
v0.67.0
v0.67.1
v0.67.2
v0.67.3
v0.67.4
v0.68.0
v0.68.1
v0.68.2
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v0.9.1

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.1.2
v1.10.0
v1.10.1
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.12.0
v1.12.1
v1.12.2
v1.12.3
v1.12.4
v1.12.5
v1.13.0
v1.13.1
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.15.5
v1.15.6
v1.16.0
v1.16.1
v1.16.2
v1.16.3
v1.16.4
v1.16.5
v1.16.6
v1.16.7
v1.17.0
v1.18.0
v1.19.0
v1.19.1
v1.19.2
v1.19.3
v1.19.4
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.20.0
v1.20.1
v1.20.2
v1.20.3
v1.21.0
v1.21.1
v1.21.2
v1.21.3
v1.21.4
v1.22.0
v1.23.0
v1.23.1
v1.24.0
v1.25.0
v1.25.1
v1.25.2
v1.26.0
v1.26.1
v1.26.2
v1.26.3
v1.26.4
v1.26.5
v1.27.0
v1.27.1
v1.27.10
v1.27.11
v1.27.12
v1.27.13
v1.27.14
v1.27.2
v1.27.3
v1.27.4
v1.27.5
v1.27.6
v1.27.7
v1.27.8
v1.27.9
v1.28.0
v1.29.0
v1.29.1
v1.3.0
v1.3.1
v1.3.2
v1.3.3
v1.30.0
v1.30.1
v1.31.0
v1.31.1
v1.32.0
v1.32.1
v1.4.0
v1.4.1
v1.4.2
v1.5.0
v1.6.0
v1.6.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.8.0
v1.9.0
v1.9.1
v1.9.2
v1.9.3

v2.*

v2.0.0
v2.0.0-0
v2.0.0-1
v2.0.0-2
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.10.0
v2.10.1
v2.10.2
v2.10.3
v2.10.4
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.12.1
v2.13.0
v2.13.1
v2.14.0
v2.15.0
v2.16.0
v2.16.1
v2.17.0
v2.17.1
v2.18.0
v2.18.1
v2.18.2
v2.19.0
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.22.2
v2.23.0
v2.23.1
v2.24.0
v2.25.0
v2.26.0
v2.26.1
v2.26.10
v2.26.11
v2.26.2
v2.26.3
v2.26.4
v2.26.5
v2.26.6
v2.26.7
v2.26.8
v2.26.9
v2.27.0
v2.27.1
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.30.0
v2.31.0
v2.32.0
v2.32.1
v2.33.0
v2.33.1
v2.33.2
v2.33.3
v2.34.0
v2.34.1
v2.34.2
v2.35.0
v2.35.1
v2.36.0
v2.36.1
v2.36.2
v2.37.0
v2.37.1
v2.38.0
v2.38.1
v2.38.2
v2.38.3
v2.38.4
v2.38.5
v2.39.0
v2.39.1
v2.4.0
v2.40.0
v2.41.0
v2.41.1
v2.41.2
v2.41.3
v2.41.4
v2.41.5
v2.42.0
v2.42.1
v2.42.2
v2.42.3
v2.42.4
v2.43.0
v2.43.1
v2.44.0
v2.45.0
v2.45.1
v2.45.2
v2.46.0
v2.47.0
v2.48.0
v2.49.0
v2.50.0
v2.50.1
v2.50.2
v2.50.3
v2.50.4
v2.50.5
v2.50.6
v2.51.0
v2.51.1
v2.51.2
v2.52.0
v2.52.1
v2.52.2
v2.52.3
v2.52.4
v2.52.5
v2.52.6
v2.52.7
v2.52.8
v2.53.0
v2.53.1
v2.53.2
v2.53.3
v2.54.0
v2.55.0
v2.55.1
v2.56.0
v2.56.1
v2.56.2
v2.56.3
v2.57.0
v2.58.0
v2.58.1
v2.58.2
v2.58.3
v2.59.0
v2.6.0
v2.6.1
v2.60.0
v2.60.1
v2.60.2
v2.61.0
v2.61.1
v2.62.0
v2.63.0
v2.64.0
v2.65.0
v2.66.0
v2.66.1
v2.67.0
v2.67.1
v2.67.2
v2.67.3
v2.68.0
v2.69.0
v2.69.1
v2.69.2
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v2.7.4
v2.7.5
v2.7.6
v2.70.0
v2.70.1
v2.70.2
v2.71.0
v2.71.1
v2.72.0
v2.73.0
v2.74.0
v2.74.1
v2.75.0
v2.75.1
v2.75.3
v2.75.4
v2.75.5
v2.75.6
v2.75.7
v2.76.0
v2.77.0
v2.77.1
v2.77.2
v2.77.3
v2.78.0
v2.78.1
v2.79.0
v2.79.1
v2.8.0
v2.8.1
v2.8.2
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.1
v3.1.0
v3.10.0
v3.10.1
v3.11.0
v3.12.0
v3.12.1
v3.13.0
v3.14.0
v3.15.0
v3.16.0
v3.17.0
v3.17.1
v3.17.2
v3.17.3
v3.18.0
v3.19.0
v3.19.1
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.20.0
v3.20.1
v3.20.2
v3.20.3
v3.20.4
v3.20.5
v3.20.6
v3.20.7
v3.21.0
v3.21.1
v3.21.2
v3.21.3
v3.21.4
v3.21.5
v3.21.6
v3.21.7
v3.21.8
v3.22.0
v3.22.1
v3.23.0
v3.23.1
v3.24.0
v3.24.1
v3.25.0
v3.25.1
v3.25.2
v3.25.3
v3.26.0
v3.26.1
v3.26.2
v3.26.3
v3.27.0
v3.27.1
v3.27.2
v3.28.0
v3.28.1
v3.29.0
v3.29.1
v3.29.2
v3.29.3
v3.29.4
v3.3.0
v3.4.0
v3.5.0
v3.5.1
v3.6.0
v3.7.0
v3.7.1
v3.7.2
v3.7.3
v3.7.4
v3.7.5
v3.8.0
v3.8.1
v3.9.0
v3.9.1

v4.*

v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.1.1
v4.1.2
v4.1.3
v4.1.4
v4.1.5
v4.1.6
v4.10.0
v4.11.0
v4.12.0
v4.12.1
v4.13.0
v4.13.1
v4.13.2
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.15.0
v4.16.0
v4.16.1
v4.16.2
v4.16.3
v4.16.4
v4.17.0
v4.17.1
v4.17.2
v4.18.0
v4.18.1
v4.19.0
v4.19.1
v4.19.2
v4.2.0
v4.20.0
v4.21.0
v4.21.1
v4.21.2
v4.21.3
v4.22.0
v4.22.1
v4.22.2
v4.22.3
v4.3.0
v4.3.1
v4.4.0
v4.4.1
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.7.0
v4.8.0
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v4.9.6