CVE Feed

    Dashboard / CVE / CVE-2024-47068

    CVE-2024-47068

    Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with properties from `import.meta` (e.g., `import.meta.url`) in `cjs`/`umd`/`iife` format. The DOM Clobbering gadget can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an `img` tag with an unsanitized `name` attribute) are present. Versions 2.79.2, 3.29.5, and 4.22.4 contain a patch for the vulnerability.

    Published:Sep 23, 2024
    Last Modified:Oct 29, 2024
    EPS:Sep 23, 2024
    EPSS Score:0.00058
    CVSS Score:6.1

    Affected Products

    Vendor
    Redhat
    Product
    Openshift Distributed Tracing
    Vendor
    Redhat
    Product
    Rhdh
    Vendor
    Rollup
    Product
    Rollup
    Vendor
    Rollupjs
    Product
    Rollup

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High