VDB
Sign up
MEDIUM5.3

GHSA-qcj6-vxwx-4rqv

Decidim vulnerable to data disclosure through the embed feature

Quick fix

GHSA-qcj6-vxwx-4rqv — decidim: upgrade to the fixed version with the command below.

bundle update decidim

Details

### Impact

If an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embedded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed.

### Patches

version 0.27.6

https://github.com/decidim/decidim/commit/1756fa639ef393ca8e8bb16221cab2e2e7875705

### Workarounds

Disallow access through your web server to the URLs finished with `/embed.html`

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim
Introduced in: 0Fixed in: 0.27.6
Fixbundle update decidim

References