CVE-2023-2307
published 2023-04-26CVE-2023-2307: Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.27%
18.7th percentile
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| builder.io | qwik-city | >= 0 < 0.104.0 | 0.104.0 |
| builderio | builderio_qwik | >= unspecified < 0.104.0 | 0.104.0 |
| qwik | qwik | < 0.104.0 | 0.104.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
osv·2023-04-26
CVE-2023-2307 [MEDIUM] @builder.io/qwik-city Cross-Site Request Forgery vulnerability
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
GHSA
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
ghsa·2023-04-26
CVE-2023-2307 [MEDIUM] CWE-352 @builder.io/qwik-city Cross-Site Request Forgery vulnerability
@builder.io/qwik-city Cross-Site Request Forgery vulnerability
Cross-Site Request Forgery (CSRF) in GitHub repository builderio/qwik prior to 0.104.0.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/BuilderIO/qwik/pull/3862/commits/09190b70027354baf7ad3d208df9c05a87f75f57https://huntr.dev/bounties/204ea12e-9e5c-4166-bf0e-fd49c8836917https://github.com/BuilderIO/qwik/pull/3862/commits/09190b70027354baf7ad3d208df9c05a87f75f57https://huntr.dev/bounties/204ea12e-9e5c-4166-bf0e-fd49c8836917
2023-04-26
Published