Описание
Decidim is a participatory democracy framework. In versions from 0.30.0 to before 0.30.4 and from 0.31.0.rc1 to before 0.31.0, the private data exports can lead to data leaks in case the UUID generation, causing collisions for the generated UUIDs. This issue has been patched in versions 0.30.4 and 0.31.0.
Ссылки
- Issue TrackingPatch
- Release Notes
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.30.0 (включая) до 0.30.4 (исключая)
Одно из
cpe:2.3:a:decidim:decidim:*:*:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:0.31.0:rc1:*:*:*:ruby:*:*
cpe:2.3:a:decidim:decidim:0.31.0:rc2:*:*:*:ruby:*:*
EPSS
Процентиль: 18%
0.00262
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200
Связанные уязвимости
EPSS
Процентиль: 18%
0.00262
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-200