QID 997370
Date Published: 2024-02-21
QID 997370: Rubygems (Rubygems) Security Update for decidim-templates (GHSA-f3qm-vfc3-jg6v)
The CSRF authenticity token check is currently disabled for the questionnaire templates preview as per: https://github.com/decidim/decidim/blob/3187bdfd40ea1c57c2c12512b09a7fec0b2bed08/decidim-templates/app/controllers/decidim/templates/admin/questionnaire_templates_controller.rb#L11
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-f3qm-vfc3-jg6v for updates and patch information.
Vendor References
- GHSA-f3qm-vfc3-jg6v -
github.com/advisories/GHSA-f3qm-vfc3-jg6v
CVEs related to QID 997370
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f3qm-vfc3-jg6v | decidim-templates |
|