Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r275-j57c-7mf2

Опубликовано: 20 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Race condition in Endorsements

Impact

A race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement.

To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel.

Workarounds

Disable the Endorsement feature in the components.

Пакеты

Наименование

decidim

rubygems
Затронутые версииВерсия исправления

>= 0.10.0, < 0.26.9

0.26.9

Наименование

decidim

rubygems
Затронутые версииВерсия исправления

>= 0.27.0, < 0.27.5

0.27.5

EPSS

Процентиль: 52%
0.00287
Низкий

3.1 Low

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 3.1
nvd
почти 2 года назад

Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement. To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel. Versions 0.26.9, 0.27.5, and 0.28.0 contain a patch for this issue. As a workaround, disable the Endorsement feature in the components.

EPSS

Процентиль: 52%
0.00287
Низкий

3.1 Low

CVSS3

Дефекты

CWE-362