Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-47068

20
FAUCET Score

CVE-2024-47068 is a medium-severity DOM Clobbering vulnerability affecting Rollup, a JavaScript module bundler, in versions prior to 2.79.2, 3.29.5, and 4.22.4. This flaw can lead to cross-site scripting (XSS) when bundling scripts using import.meta properties in cjs/umd/iife formats, allowing attacker-controlled HTML elements to manipulate the DOM. The vulnerability has a CVSS score of 6.1 (Medium) due to its network attack vector and low attack complexity, requiring user interaction but potentially leading to partial loss of confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.59.0, < 2.79.2CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*
>= 3.0.0, < 3.29.5CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*
>= 4.0.0, < 4.22.4CPE matchmatch criteria
cpe:2.3:a:rollupjs:rollup:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.70%
Probability of exploitation in next 30 days
EPSS Percentile
49.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0070 is in the 55th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: rollupFixed in: 4.22.4
npmpatch availablevia ghsa
Product: rollupFixed in: 3.29.5
npmpatch availablevia ghsa
Product: rollupFixed in: 2.79.2
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.4Fixed in: rhosdt/jaeger-query-rhel8:sha256:648d95c1a6736055910cd901c7e80d82d0e8bad71531373293144d0d6682b994
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.5Fixed in: rhdh/rhdh-hub-rhel9:sha256:56bfbb2328f42e91d0462e142f3434e5d771737defbc07d8a21dbdf50e468665
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift distributed tracing 3.4Fixed in: rhosdt/jaeger-query-rhel8:sha256:78b4c8cb7e68b33fbd0cfb502a2d4e3ca09eeb6168d525c80ae0a45775364952
View patch
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for Applications 7Fixed in: mta/mta-ui-rhel9
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 3Fixed in: rhosdt/jaeger-query-rhel8
redhatno patchvia redhat_api
Product: Network Observability OperatorFixed in: network-observability/network-observability-console-plugin-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-controller
redhatend of lifevia redhat_api
Product: Migration Toolkit for RuntimesFixed in: rollup

Vendor Advisories (2)

npmGHSA-gcx4-mw62-g8wmhigh

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

Sep 23, 2024
redhatCVE-2024-47068Moderate

rollup: DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

Sep 23, 2024

References

github.com / rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts
Product
github.com / rollup/rollup/blob/b86ffd776cfa906573d36c3f019316d02445d9ef/src/ast/nodes/MetaProperty.ts
Product
github.com / rollup/rollup/commit/2ef77c00ec2635d42697cff2c0567ccc8db34fb4
Patch
github.com / rollup/rollup/commit/e2552c9e955e0a61f70f508200ee9f752f85a541
Patch
github.com / rollup/rollup/security/advisories/GHSA-gcx4-mw62-g8wm
ExploitVendor Advisory