-
Notifications
You must be signed in to change notification settings - Fork 17
fix(deps): update dependency webpack-dev-middleware to v5 [security] #5373
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: yarn.lock |
398a6a5 to
1c3d0fb
Compare
1c3d0fb to
9d0c985
Compare
9d0c985 to
e2060f3
Compare
430c158 to
e8de645
Compare
eb4093c to
1198166
Compare
1198166 to
ca1f55a
Compare
ca1f55a to
4435207
Compare
|
4435207 to
62748b6
Compare
62748b6 to
40378cd
Compare
af90a40 to
6918d8d
Compare
2a6bf5a to
c5cc8bd
Compare
c5cc8bd to
332cf85
Compare
332cf85 to
83b453f
Compare
7b32b29 to
a30ff17
Compare
516a00e to
dd908d4
Compare
fed3b9f to
680ecdc
Compare
680ecdc to
a84ac84
Compare
a84ac84 to
92a9eb0
Compare
92a9eb0 to
c4c0f1f
Compare
This PR contains the following updates:
^1.9.0->^5.0.0GitHub Vulnerability Alerts
CVE-2024-29180
Summary
The webpack-dev-middleware middleware does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine.
Details
The middleware can either work with the physical filesystem when reading the files or it can use a virtualized in-memory memfs filesystem.
If writeToDisk configuration option is set to true, the physical filesystem is used:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/setupOutputFileSystem.js#L21
The getFilenameFromUrl method is used to parse URL and build the local file path.
The public path prefix is stripped from the URL, and the unsecaped path suffix is appended to the outputPath:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/getFilenameFromUrl.js#L82
As the URL is not unescaped and normalized automatically before calling the midlleware, it is possible to use %2e and %2f sequences to perform path traversal attack.
PoC
A blank project can be created containing the following configuration file webpack.config.js:
module.exports = { devServer: { devMiddleware: { writeToDisk: true } } };When started, it is possible to access any local file, e.g. /etc/passwd:
$ curl localhost:8080/public/..%2f..%2f..%2f..%2f../etc/passwdImpact
The developers using webpack-dev-server or webpack-dev-middleware are affected by the issue. When the project is started, an attacker might access any file on the developer's machine and exfiltrate the content (e.g. password, configuration files, private source code, ...).
If the development server is listening on a public IP address (or 0.0.0.0), an attacker on the local network can access the local files without any interaction from the victim (direct connection to the port).
If the server allows access from third-party domains (CORS, Allow-Access-Origin: * ), an attacker can send a malicious link to the victim. When visited, the client side script can connect to the local server and exfiltrate the local files.
Recommendation
The URL should be unescaped and normalized before any further processing.
Release Notes
webpack/webpack-dev-middleware (webpack-dev-middleware)
v5.3.4Compare Source
5.3.4 (2024-03-20)
Bug Fixes
v5.3.3Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.2Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.1Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.0Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.2.2Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.1Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.0Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.1.0Compare Source
Features
Rangeheader is present (e8b21f0)Bug Fixes
mempackage (#1027) (0d55268)v5.0.0Compare Source
⚠ BREAKING CHANGES
Node.jsversion is12.13.0(#928) (4cffeff)v4.3.0Compare Source
Features
getFilenameFromUrlto API (#911) (1edc726)Bug Fixes
v4.2.0Compare Source
Features
headersoption to accept function (#897) (966afb3)v4.1.0Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.4Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.3Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.2Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.1Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.0Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v3.7.3Compare Source
3.7.3 (2020-12-15)
Bug Fixes
v3.7.2Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.7.1Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.7.0Compare Source
Bug Fixes
options.jsonfile (#589) (41d6264)4.0.0-rc.0 (2020-02-19)
Bug Fixes
output.pathandoutput.publicPathoptions from the configurationstatsoption from the configurationwatchOptionsoption from the configurationwriteToDiskoption now correctly works in multi-compiler modeoutputFileSystemoption now correctly works in multi-compiler mode[hash]/[fullhash]inoutput.pathandoutput.publicPathContent-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8Features
webpackloggermemfspackageBREAKING CHANGES
10.13.0publicPathis taken from the value of theoutput.publicPathoption from the configuration (webpack.config.js)statsoption was removed, the default value of thestatsoption is taken from the value of thestatsoption from the configuration (webpack.config.js)watchOptionswas removed, the default value of thewatchOptionsoption is taken from the value of thewatchOptionsoption from the configuration (webpack.config.js)Content-Typeheader doesn't havecharset=utf-8value for custom MIME types and MIME types which can be nonutf-8fsoption was renamed to theoutputFileSystemoptionlazyoption was removed without replacementlogger,logLevelandlogTimeoptions were removed without replacement. You can setup thelevelvalue using{ infrastructureLogging: { level: 'warn' } }, please read https://webpack.js.org/configuration/other-options/#infrastructurelogging. You can use theinfrastructurelog(infrastructureLoginwebpack@5) hook to customize logs. Thelogproperty in the middleware context was renamed tologgermimeTypesoption first requires you to specify an extension and then a content-type -{ mimeTypes: { phtml: 'text/html' } }forceoption from themimeTypesoption was removed without replacementreporteroption was removed without replacementgetFilenameFromUrlmethod was removed from the APIlocalsnow underres.locals.webpack- useres.locals.webpack.statsfor accessstatsandres.locals.webpack.outputFileSystemto accessoutputFileSystem3.7.2 (2019-09-28)
Bug Fixes
writeToDiskused (#472) (6730076)3.7.1 (2019-09-03)
Bug Fixes
writeToFileoption has compatibility with webpack@5 (#459) (5c90e1e)v3.6.2Compare Source
Bug Fixes
res.getHeaderand set the correct Content-Type (#385) (56dc705)v3.6.1Compare Source
Bug Fixes
v3.6.0Compare Source
Features
v3.5.2Compare Source
Bug Fixes
usdzfile type (#357) (b135b3d)v3.5.1Compare Source
Bug Fixes
v3.5.0Compare Source
Bug Fixes
Features
mimeTypes(possible to useforceoption) (#349) (e56a181)v3.4.0Compare Source
Bug FixesunhandledRejection(#340) (f0a8e3e)url-joinwithpath.posix.join(#334) (d75802b)v3.3.0Compare Source
Features
response.locals.fs) (#337) (f9a138e)v3.2.0Compare Source
Bug Fixes
Features
methodsoption (options.methods) (#319) (fe6bb86)v3.1.3Compare Source
Bugfixes
v3.1.2Compare Source
Updates
v3.1.1Compare Source
Bugfixes
v3.1.0Compare Source
Bugfixes
d26c67c)Features
v3.0.1Compare Source
v3.0.0Compare Source
Updates
Breaking Changes
watchOffsetoption has been removed and the README has been updated with alternative means of accomplishing the same result for this module and webpack v4.middleware.webpacknow returns aPromisethat should be handled with.thenwhen needing to perform other actions, like adding additional middleware.v2.0.6Compare Source
v2.0.5Compare Source
v2.0.4Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
Updates
webpack-log, removed dependencies related to the previous logging implementation.v2.0.1Compare Source
Publish to correct
package.json.v2.0.0Compare Source
This major release introduces a comprehensive refactor of the codebase and move to leverage more ES6 as supported by Node 6+. It also introduced a number of breaking changes, as outlined below.
Node Version Support
webpack-dev-middleware version 2 and higher will only support Node 6.x and higher. Active
LTS for Node 4.x ended October 31st, 2017 and entered maintenance on that date.
Likewise, the version 1.x branch of webpack-dev-middleware will enter maintenance on
that date.
Informative Changes
log-leveland follows the same patterns aswebpack-dev-server.Breaking Changes
watchDelayoption was previous deprecated and has now been removed.reportTimeoption renamed tologTimenoInfooption removed in favor of setting alogLevelhigher than'info'quietoption removed in favor oflogLevel: 'silent'reportersignature changed toreporter(middlewareOptions, reporterOptions)Configuration
📅 Schedule: Branch creation - "" in timezone US/Eastern, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.