VDB
Sign up
MEDIUM6.8

GHSA-rx9f-5ggv-5rh6

Decidim::Admin vulnerable to cross-site scripting (XSS) in the admin activity log

Quick fix

GHSA-rx9f-5ggv-5rh6 — decidim-admin: upgrade to the fixed version with the command below.

bundle update decidim-admin

Details

### Impact The admin panel is subject to potential XSS attach in case an admin assigns a valuator to a proposal, or does any other action that generates an admin activity log where one of the resources has an XSS crafted.

### Patches

N/A

### Workarounds

Redirect the pages /admin and /admin/logs to other admin pages to prevent this access (i.e. `/admin/organization/edit`)

### References

OWASP ASVS v4.0.3-5.1.3

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/decidim-admin
Introduced in: 0Fixed in: 0.27.7
Fixbundle update decidim-admin
RubyGems/decidim-admin
Introduced in: 0.28.0Fixed in: 0.28.2
Fixbundle update decidim-admin

References