Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Advisories: GSA_kwCzR0hTQS1obTdmLXJxN3Etajl4cM4AAxFC
@builder.io/qwik vulnerable to Cross-site Scripting
@builder.io/qwik prior to version 0.16.2 is vulnerable to cross-site scripting due to attribute names and the class attribute values not being properly handled.
Permalink: https://github.com/advisories/GHSA-hm7f-rq7q-j9xpSource: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 9 days ago
Updated: 3 days ago
CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Identifiers: GHSA-hm7f-rq7q-j9xp, CVE-2023-0410
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-0410
- https://github.com/builderio/qwik/commit/4b2f89dbbd2bc0a2c92eae1a49bdd186e589151a
- https://huntr.dev/bounties/2da583f0-7f66-4ba7-9bed-8e7229aa578e
- https://github.com/advisories/GHSA-hm7f-rq7q-j9xp
Affected Packages
npm:@builder.io/qwik
Versions: < 0.16.2Fixed in: 0.16.2