File tree 1 file changed +43
-0
lines changed
1 file changed +43
-0
lines changed Original file line number Diff line number Diff line change
1
+ ---
2
+ layout : advisory
3
+ title : ' CVE-2024-41673 (decidim): Decidim has a cross-site scripting vulnerability
4
+ in the version control page'
5
+ comments : false
6
+ categories :
7
+ - decidim
8
+ advisory :
9
+ gem : decidim
10
+ cve : 2024-41673
11
+ ghsa : cc4g-m3g7-xmw8
12
+ url : https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
13
+ title : Decidim has a cross-site scripting vulnerability in the version control page
14
+ date : 2024-10-01
15
+ description : |
16
+ ### Impact
17
+
18
+ The version control feature used in resources is subject to potential
19
+ cross-site scripting (XSS) attack through a malformed URL.
20
+
21
+ ### Workarounds
22
+
23
+ Not available
24
+
25
+ ### References
26
+
27
+ OWASP ASVS v4.0.3-5.1.3
28
+
29
+ ### Credits
30
+
31
+ This issue was discovered in a security audit organized by
32
+ [Open Source Politics](https://opensourcepolitics.eu/)
33
+ against Decidim done during July 2025.
34
+ cvss_v3 : 7.1
35
+ patched_versions :
36
+ - " >= 0.27.8"
37
+ related :
38
+ url :
39
+ - https://nvd.nist.gov/vuln/detail/CVE-2024-41673
40
+ - https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
41
+ - https://github.com/decidim/decidim/commit/8a18c8b1ee85a1b35ee0d8d5893f218695d15637
42
+ - https://github.com/advisories/GHSA-cc4g-m3g7-xmw8
43
+ ---
You can’t perform that action at this time.
0 commit comments