CVE-2024-32034

decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted. This issue has been addressed in release version 0.27.7, 0.28.2, and newer. Users are advised to upgrade. Users unable to upgrade may redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`).
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:0.28.0:-:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:0.28.1:*:*:*:*:ruby:*:*

History

29 Sep 2024, 00:14

Type Values Removed Values Added
References () https://github.com/decidim/decidim/commit/23fc8d702a4976727f78617f5e42353d67931645 - () https://github.com/decidim/decidim/commit/23fc8d702a4976727f78617f5e42353d67931645 - Patch
References () https://github.com/decidim/decidim/commit/9d79f09a2d38c87feb28725670d6cc1f55c22072 - () https://github.com/decidim/decidim/commit/9d79f09a2d38c87feb28725670d6cc1f55c22072 - Patch
References () https://github.com/decidim/decidim/commit/e494235d559be13dd1f8694345e6f6bba762d1c0 - () https://github.com/decidim/decidim/commit/e494235d559be13dd1f8694345e6f6bba762d1c0 - Patch
References () https://github.com/decidim/decidim/commit/ff755e23814aeb56e9089fc08006a5d3faee47b6 - () https://github.com/decidim/decidim/commit/ff755e23814aeb56e9089fc08006a5d3faee47b6 - Patch
References () https://github.com/decidim/decidim/security/advisories/GHSA-rx9f-5ggv-5rh6 - () https://github.com/decidim/decidim/security/advisories/GHSA-rx9f-5ggv-5rh6 - Vendor Advisory
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 4.8
First Time Decidim decidim
Decidim
CPE cpe:2.3:a:decidim:decidim:0.28.1:*:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:0.28.0:-:*:*:*:ruby:*:*

20 Sep 2024, 12:31

Type Values Removed Values Added
Summary
  • (es) Decidim es una democracia participativa, participación ciudadana y gobierno abierto de código abierto y gratuito para ciudades y organizaciones. El panel de administración está sujeto a posibles ataques de cross site scripting (XSS) en caso de que un administrador asigne un evaluador a una propuesta o realice cualquier otra acción que genere un registro de actividad de administración donde uno de los recursos tenga un XSS creado. Este problema se ha solucionado en las versiones de lanzamiento 0.27.7, 0.28.2 y posteriores. Se recomienda a los usuarios que actualicen. Los usuarios que no puedan actualizar pueden redirigir las páginas /admin y /admin/logs a otras páginas de administración para evitar este acceso (es decir, `/admin/organization/edit`).

16 Sep 2024, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-16 19:16

Updated : 2024-09-29 00:14


NVD link : CVE-2024-32034

Mitre link : CVE-2024-32034

CVE.ORG link : CVE-2024-32034


JSON object : View

Products Affected

decidim

  • decidim
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')