Moderate severityNVD Advisory· Published Apr 26, 2023· Updated Jan 31, 2025
Cross-Site Request Forgery (CSRF) in builderio/qwik
CVE-2023-2307
Description
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@builder.io/qwik-citynpm | < 0.104.0 | 0.104.0 |
Affected products
1- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/advisories/GHSA-c54w-7j5f-xg98ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-2307ghsaADVISORY
- github.com/BuilderIO/qwik/commit/f434d335277418f5bd8dd90fae5cb089e1230cb8ghsaWEB
- github.com/BuilderIO/qwik/pull/3862/commits/09190b70027354baf7ad3d208df9c05a87f75f57ghsaWEB
- github.com/BuilderIO/qwik/releases/tag/v0.104.0ghsaWEB
- huntr.dev/bounties/204ea12e-9e5c-4166-bf0e-fd49c8836917ghsaWEB
News mentions
0No linked articles in our index yet.