Decidim是Decidim组织开源的一个参与式民主框架,用 Ruby on Rails 编写。 Decidim 0.30.9之前版本、0.31.0至0.31.5之前版本和0.32.0.rc1至0.32.0.rc2之前版本存在信息泄露漏洞,该漏洞源于身份文档验证管理UI通过可重用的签名Active Storage磁盘URL嵌入验证附件,且未通过授权检查控制器,导致任何人获取URL后可在签名有效期内无需认证下载扫描文档,造成信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45414 | 8.5 HIGH | Decidim: JWT-backed authentication can be replayed across organizations |
| CVE-2026-45573 | 6.4 MEDIUM | Decidim: Push subscriptions can be abused for server-side requests |
| CVE-2026-45415 | 6.0 MEDIUM | Decidim: CSV census record endpoints improper authorization |
| CVE-2026-45572 | 4.8 MEDIUM | Decidim: HTML content blocks allow stored script execution |
No comments yet