漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Decidim: Private exports can be downloaded through reusable links
Vulnerability Description
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the normal download_your_data flow requires the requester to be logged in as the export owner, but the resulting Active Storage blob redirect URL can be replayed without authentication by anyone who obtains it. This is because Decidim::DownloadYourDataController#download_file authenticates the export owner but redirects to a signed Active Storage blob URL that is no longer bound to the owner session. This issue is fixed in versions 0.30.9, 0.31.5, and 0.32.0.rc2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Decidim 信息泄露漏洞
Vulnerability Description
Decidim是Decidim组织开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.30.9之前版本、0.31.0版本至0.31.5之前版本和0.32.0.rc1版本至0.32.0.rc2之前版本存在安全漏洞,该漏洞源于下载本人数据流程中对重定向URL的认证不当,导致已签名的Active Storage blob URL可被未经身份验证的任何人重放,造成信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A