PT-2024-19589 · Livewire · Livewire

Published

2024-02-01

·

Updated

2024-08-01

·

CVE-2024-22859

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions livewire versions prior to 3.0.4
Description A Cross-Site Request Forgery (CSRF) issue allows remote attackers to execute arbitrary code via the getCsrfToken function. The vendor disputes this, stating that the 5d88731 commit fixes a usability problem, not a security problem.
Recommendations For versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider disabling the getCsrfToken function until a patch is available.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-22859
GHSA-2CJH-75GP-34GC

Affected Products

Livewire