Skip to content

Broken access control in templates

Critical
andreslucena published GHSA-639h-86hw-qcjq Oct 5, 2023

Package

bundler decidim (RubyGems)

Affected versions

>= 0.23.2

Patched versions

0.27.4, 0.26.8
bundler decidim-templates (RubyGems)
>= 0.23.2
0.27.4, 0.26.8

Description

Impact

The templates module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys.

Patches

Not available yet

Severity

Critical
9.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

CVE ID

CVE-2023-36465

Weaknesses

No CWEs

Credits