CVE-2023-1283
published 2023-03-08CVE-2023-1283: Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.15%
63.5th percentile
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| builder.io | qwik | >= 0 < 0.21.0 | 0.21.0 |
| builderio | builderio_qwik | >= unspecified < 0.21.0 | 0.21.0 |
| keylime | keylime | >= 0 < 7.2.5 | 7.2.5 |
| qwik | qwik | < 0.21.0 | 0.21.0 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
keylime fails to flag device as untrusted when signature does not validate
ghsa·2023-07-19
CVE-2023-3674 [MEDIUM] CWE-1283 keylime fails to flag device as untrusted when signature does not validate
keylime fails to flag device as untrusted when signature does not validate
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
OSV
builderio/qwik is vulnerable to code injection
osv·2023-03-09
CVE-2023-1283 [CRITICAL] builderio/qwik is vulnerable to code injection
builderio/qwik is vulnerable to code injection
Code Injection in GitHub repository builderio/qwik prior to 0.21.0. The Function deserializer can be accessed using the pureServerFunction feature. This allows any Javascript code to be run by node.js.
GHSA
builderio/qwik is vulnerable to code injection
ghsa·2023-03-09
CVE-2023-1283 [CRITICAL] CWE-94 builderio/qwik is vulnerable to code injection
builderio/qwik is vulnerable to code injection
Code Injection in GitHub repository builderio/qwik prior to 0.21.0. The Function deserializer can be accessed using the pureServerFunction feature. This allows any Javascript code to be run by node.js.
Red Hat
keylime: Attestation failure when the quote's signature does not validate
vendor_redhat·2023-07-12·CVSS 2.3
CVE-2023-3674 [LOW] CWE-1283 keylime: Attestation failure when the quote's signature does not validate
keylime: Attestation failure when the quote's signature does not validate
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/BuilderIO/qwik/pull/3249/commits/4d9ba6e098ae6e537aa55abb6b8369bb670ffe66https://huntr.dev/bounties/63f1ff91-48f3-4886-a179-103f1ddd8ff8https://github.com/BuilderIO/qwik/pull/3249/commits/4d9ba6e098ae6e537aa55abb6b8369bb670ffe66https://huntr.dev/bounties/63f1ff91-48f3-4886-a179-103f1ddd8ff8
2023-03-08
Published