-
Notifications
You must be signed in to change notification settings - Fork 1
fix(deps): update dependency webpack-dev-middleware to v5 [security] #61
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-webpack-dev-middleware-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
3a2b362 to
f1ff602
Compare
f1ff602 to
5b38b7d
Compare
5b38b7d to
8a8de5b
Compare
8a8de5b to
22f6c75
Compare
22f6c75 to
d573cbf
Compare
d573cbf to
b0b3cb8
Compare
b0b3cb8 to
15e303e
Compare
15e303e to
0177ef4
Compare
0177ef4 to
419970a
Compare
419970a to
bfa6fa1
Compare
bfa6fa1 to
09172b5
Compare
09172b5 to
bf9a1c9
Compare
bf9a1c9 to
5d7411e
Compare
5d7411e to
1371663
Compare
1371663 to
cba0a64
Compare
812b264 to
fd4faae
Compare
fd4faae to
fcc8c19
Compare
fcc8c19 to
3d8422d
Compare
3d8422d to
ada273a
Compare
ada273a to
01b659f
Compare
01b659f to
923a064
Compare
923a064 to
8f235a8
Compare
8f235a8 to
78ffa89
Compare
78ffa89 to
576a4b7
Compare
576a4b7 to
dca44e4
Compare
5d1dc4d to
62cadf9
Compare
62cadf9 to
de75266
Compare
de75266 to
3cc78f5
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^3.2.0→^5.3.4GitHub Vulnerability Alerts
CVE-2024-29180
Summary
The webpack-dev-middleware middleware does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine.
Details
The middleware can either work with the physical filesystem when reading the files or it can use a virtualized in-memory memfs filesystem.
If writeToDisk configuration option is set to true, the physical filesystem is used:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/setupOutputFileSystem.js#L21
The getFilenameFromUrl method is used to parse URL and build the local file path.
The public path prefix is stripped from the URL, and the unsecaped path suffix is appended to the outputPath:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/getFilenameFromUrl.js#L82
As the URL is not unescaped and normalized automatically before calling the midlleware, it is possible to use %2e and %2f sequences to perform path traversal attack.
PoC
A blank project can be created containing the following configuration file webpack.config.js:
module.exports = { devServer: { devMiddleware: { writeToDisk: true } } };When started, it is possible to access any local file, e.g. /etc/passwd:
$ curl localhost:8080/public/..%2f..%2f..%2f..%2f../etc/passwdImpact
The developers using webpack-dev-server or webpack-dev-middleware are affected by the issue. When the project is started, an attacker might access any file on the developer's machine and exfiltrate the content (e.g. password, configuration files, private source code, ...).
If the development server is listening on a public IP address (or 0.0.0.0), an attacker on the local network can access the local files without any interaction from the victim (direct connection to the port).
If the server allows access from third-party domains (CORS, Allow-Access-Origin: * ), an attacker can send a malicious link to the victim. When visited, the client side script can connect to the local server and exfiltrate the local files.
Recommendation
The URL should be unescaped and normalized before any further processing.
Release Notes
webpack/webpack-dev-middleware (webpack-dev-middleware)
v5.3.4Compare Source
5.3.4 (2024-03-20)
Bug Fixes
v5.3.3Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.2Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.1Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.0Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.2.2Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.1Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.0Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.1.0Compare Source
Features
Rangeheader is present (e8b21f0)Bug Fixes
mempackage (#1027) (0d55268)v5.0.0Compare Source
⚠ BREAKING CHANGES
Node.jsversion is12.13.0(#928) (4cffeff)v4.3.0Compare Source
Features
getFilenameFromUrlto API (#911) (1edc726)Bug Fixes
v4.2.0Compare Source
Features
headersoption to accept function (#897) (966afb3)v4.1.0Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.4Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.3Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.2Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.1Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.0Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v3.7.3Compare Source
3.7.3 (2020-12-15)
Bug Fixes
v3.7.2Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.7.1Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.7.0Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.6.2Compare Source
Bug Fixes
res.getHeaderand set the correct Content-Type (#385) (56dc705)v3.6.1Compare Source
Bug Fixes
v3.6.0Compare Source
Features
v3.5.2Compare Source
Bug Fixes
usdzfile type (#357) (b135b3d)v3.5.1Compare Source
Bug Fixes
v3.5.0Compare Source
Bug Fixes
Features
mimeTypes(possible to useforceoption) (#349) (e56a181)v3.4.0Compare Source
Bug FixesunhandledRejection(#340) (f0a8e3e)url-joinwithpath.posix.join(#334) (d75802b)v3.3.0Compare Source
Features
response.locals.fs) (#337) (f9a138e)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.