{"id":"GHSA-qwvp-268g-jjm8","summary":"Data Leakage Vulnerability in livewire/livewire","details":"livewire/livewire versions greater than 2.2.4 and less than 2.2.6 are affected by a data leakage vulnerability. The `$this-\u003evalidate()` method, which is expected to return only the validated dataset, was returning all properties of the Livewire component. This regression introduced a security risk, allowing unvalidated data to be exposed, which could lead to unexpected behavior and potential security issues.\n\n","modified":"2024-11-29T05:28:26.022746Z","published":"2024-05-15T22:28:49Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-15T22:28:49Z"},"references":[{"type":"WEB","url":"https://github.com/livewire/livewire/commit/6929f5882138a98187c196ce66cc689712c000af"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/livewire/livewire/2020-09-22-1.yaml"},{"type":"PACKAGE","url":"https://github.com/livewire/livewire"},{"type":"WEB","url":"https://github.com/livewire/livewire/releases/tag/v2.2.6"}],"affected":[{"package":{"name":"livewire/livewire","ecosystem":"Packagist","purl":"pkg:composer/livewire/livewire"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.5"},{"fixed":"2.2.6"}]}],"versions":["v2.2.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-qwvp-268g-jjm8/GHSA-qwvp-268g-jjm8.json"}}],"schema_version":"1.9.0"}