File tree Expand file tree Collapse file tree 1 file changed +43
-0
lines changed Expand file tree Collapse file tree 1 file changed +43
-0
lines changed Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2024-41673 (decidim): Decidim has a cross-site scripting vulnerability
4+ in the version control page'
5+ comments : false
6+ categories :
7+ - decidim
8+ advisory :
9+ gem : decidim
10+ cve : 2024-41673
11+ ghsa : cc4g-m3g7-xmw8
12+ url : https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
13+ title : Decidim has a cross-site scripting vulnerability in the version control page
14+ date : 2024-10-01
15+ description : |
16+ ### Impact
17+
18+ The version control feature used in resources is subject to potential
19+ cross-site scripting (XSS) attack through a malformed URL.
20+
21+ ### Workarounds
22+
23+ Not available
24+
25+ ### References
26+
27+ OWASP ASVS v4.0.3-5.1.3
28+
29+ ### Credits
30+
31+ This issue was discovered in a security audit organized by
32+ [Open Source Politics](https://opensourcepolitics.eu/)
33+ against Decidim done during July 2025.
34+ cvss_v3 : 7.1
35+ patched_versions :
36+ - " >= 0.27.8"
37+ related :
38+ url :
39+ - https://nvd.nist.gov/vuln/detail/CVE-2024-41673
40+ - https://github.com/decidim/decidim/security/advisories/GHSA-cc4g-m3g7-xmw8
41+ - https://github.com/decidim/decidim/commit/8a18c8b1ee85a1b35ee0d8d5893f218695d15637
42+ - https://github.com/advisories/GHSA-cc4g-m3g7-xmw8
43+ ---
You can’t perform that action at this time.
0 commit comments