Junglewise Threat Intelligence

CVE-2023-2307: Builder.io qwik-city cross-site request forgery

CVE-2023-2307 · Severity: low · CVSS 3 · Published 2023-04-26

Technologies: @builder.io/qwik-city (npm), Builder.Io Qwik-City. Vendors: npm, Builder.Io.

Executive brief

@builder.io/qwik-city is a web framework for building fast server-side rendered applications. A cross-site request forgery (CSRF) vulnerability in versions prior to 0.104.0 could allow attackers to trick users into performing unintended actions on vulnerable applications, potentially compromising user data or triggering unauthorized state changes.

Technical details

The vulnerability is a cross-site request forgery (CWE-352) in @builder.io/qwik-city that stems from improper handling of relative protocol URLs, which could bypass CSRF protections. Specifically, URLs with a relative protocol (e.g., "//attacker.com") were not properly validated, allowing attackers to craft malicious requests. The attack requires user interaction (the victim must click a malicious link or visit a malicious page) but is network-based with no authentication required. An attacker can cause the victim's browser to make unintended requests to the vulnerable application. The vulnerability was fixed in version 0.104.0 released on 2023-04-26.

Affected products

  • Builder.io qwik-city prior to 0.104.0

Timeline

  • 2023-04-26: disclosed
  • 2023-04-26: patched: Fixed in version 0.104.0

References

Related threats