MEDIUM4.7
GHSA-c54w-7j5f-xg98
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
Quick fix
GHSA-c54w-7j5f-xg98 — @builder.io/qwik-city: upgrade to the fixed version with the command below.
npm install @builder.io/qwik-city@0.104.0Details
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@builder.io/qwik-city
Introduced in:
0Fixed in: 0.104.0Fix
npm install @builder.io/qwik-city@0.104.0References
- https://nvd.nist.gov/vuln/detail/CVE-2023-2307[ADVISORY]
- https://github.com/BuilderIO/qwik/pull/3862/commits/09190b70027354baf7ad3d208df9c05a87f75f57[WEB]
- https://github.com/BuilderIO/qwik/commit/f434d335277418f5bd8dd90fae5cb089e1230cb8[WEB]
- https://github.com/BuilderIO/qwik/releases/tag/v0.104.0[WEB]
- https://github.com/builderio/qwik[PACKAGE]
- https://huntr.dev/bounties/204ea12e-9e5c-4166-bf0e-fd49c8836917[WEB]