{"id":"GHSA-qwvp-268g-jjm8","aliases":[],"url":"https://o3.security/vulnerability/GHSA-qwvp-268g-jjm8","summary":"Data Leakage Vulnerability in livewire/livewire","details":"livewire/livewire versions greater than 2.2.4 and less than 2.2.6 are affected by a data leakage vulnerability. The `$this->validate()` method, which is expected to return only the validated dataset, was returning all properties of the Livewire component. This regression introduced a security risk, allowing unvalidated data to be exposed, which could lead to unexpected behavior and potential security issues.\n\n","published":"2024-05-15T22:28:49Z","modified":"2024-11-29T05:28:26.022746Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"livewire/livewire","fixedVersion":"2.2.6"}],"fix":{"url":"https://github.com/livewire/livewire/commit/6929f5882138a98187c196ce66cc689712c000af","label":"livewire/livewire@6929f58"},"references":[{"type":"WEB","url":"https://github.com/livewire/livewire/commit/6929f5882138a98187c196ce66cc689712c000af"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/livewire/livewire/2020-09-22-1.yaml"},{"type":"PACKAGE","url":"https://github.com/livewire/livewire"},{"type":"WEB","url":"https://github.com/livewire/livewire/releases/tag/v2.2.6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:28:26.022746Z"}}