QID 995524

Date Published: 2023-10-09

QID 995524: Rubygems (Rubygems) Security Update for decidim (GHSA-639h-86hw-qcjq)

The templates module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-639h-86hw-qcjq for updates and patch information.
    Vendor References

    CVEs related to QID 995524

    Software Advisories
    Advisory ID Software Component Link
    GHSA-639h-86hw-qcjq decidim URL Logo github.com/advisories/GHSA-639h-86hw-qcjq