LOW3.1
GHSA-r275-j57c-7mf2
Race condition in Endorsements
Quick fix
GHSA-r275-j57c-7mf2 — decidim: upgrade to the fixed version with the command below.
bundle update decidimDetails
### Impact
A race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement.
To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel. ### Workarounds
Disable the Endorsement feature in the components.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/decidim/decidim/security/advisories/GHSA-r275-j57c-7mf2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47634[ADVISORY]
- https://github.com/decidim/decidim/commit/5c5ee7a50d75c10643dd8c495e2517641e4d74db[WEB]
- https://github.com/decidim/decidim/commit/7b840d2c37a562709f4481db644d8c43add28536[WEB]
- https://github.com/decidim/decidim[PACKAGE]
- https://github.com/decidim/decidim/releases/tag/v0.26.9[WEB]
- https://github.com/decidim/decidim/releases/tag/v0.27.5[WEB]
- https://github.com/decidim/decidim/releases/tag/v0.28.0[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim/CVE-2023-47634.yml[WEB]