VDB
Sign up
HIGH8.1

GHSA-5652-92r9-3fx9

Decidim Cross-site Scripting vulnerability in the processes filter

Quick fix

GHSA-5652-92r9-3fx9 — decidim: upgrade to the fixed version with the command below.

bundle update decidim

Details

### Impact

The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.

### Patches

The problem was patched in [v0.27.3](https://github.com/decidim/decidim/releases/tag/v0.27.3) and [v0.26.7](https://github.com/decidim/decidim/releases/tag/v0.26.7)

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim
Introduced in: 0.14.0Fixed in: 0.26.7
Fixbundle update decidim
RubyGems/decidim
Introduced in: 0.27.0Fixed in: 0.27.3
Fixbundle update decidim
RubyGems/decidim-core
Introduced in: 0.14.0Fixed in: 0.26.7
Fixbundle update decidim-core
RubyGems/decidim-core
Introduced in: 0.27.0Fixed in: 0.27.3
Fixbundle update decidim-core

References