QID 997432

Date Published: 2024-02-22

QID 997432: Rubygems (Rubygems) Security Update for decidim (GHSA-9w99-78rj-hmxq)

The dynamic file upload feature is subject to potential XSS attach in case the attacker manages to modify the file names of the records being uploaded to the server.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-9w99-78rj-hmxq for updates and patch information.
    Vendor References

    CVEs related to QID 997432

    Software Advisories
    Advisory ID Software Component Link
    GHSA-9w99-78rj-hmxq decidim URL Logo github.com/advisories/GHSA-9w99-78rj-hmxq