Skip to content

Commit 1cbb352

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@7b6de19
1 parent a91ea8f commit 1cbb352

File tree

1 file changed

+43
-0
lines changed

1 file changed

+43
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2024-41673 (decidim): Decidim has a cross-site scripting vulnerability
4+
in the version control page'
5+
comments: false
6+
categories:
7+
- decidim
8+
advisory:
9+
gem: decidim
10+
cve: 2024-41673
11+
ghsa: cc4g-m3g7-xmw8
12+
url: https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
13+
title: Decidim has a cross-site scripting vulnerability in the version control page
14+
date: 2024-10-01
15+
description: |
16+
### Impact
17+
18+
The version control feature used in resources is subject to potential
19+
cross-site scripting (XSS) attack through a malformed URL.
20+
21+
### Workarounds
22+
23+
Not available
24+
25+
### References
26+
27+
OWASP ASVS v4.0.3-5.1.3
28+
29+
### Credits
30+
31+
This issue was discovered in a security audit organized by
32+
[Open Source Politics](https://opensourcepolitics.eu/)
33+
against Decidim done during July 2025.
34+
cvss_v3: 7.1
35+
patched_versions:
36+
- ">= 0.27.8"
37+
related:
38+
url:
39+
- https://nvd.nist.gov/vuln/detail/CVE-2024-41673
40+
- https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
41+
- https://github.com/decidim/decidim/commit/8a18c8b1ee85a1b35ee0d8d5893f218695d15637
42+
- https://github.com/advisories/GHSA-cc4g-m3g7-xmw8
43+
---

0 commit comments

Comments
 (0)