Skip to content

Commit

Permalink
GHSA Sync: Added 2 brand new advisories
Browse files Browse the repository at this point in the history
  • Loading branch information
jasnow authored and postmodern committed Oct 6, 2023
1 parent c43d211 commit 14ff883
Show file tree
Hide file tree
Showing 2 changed files with 54 additions and 0 deletions.
27 changes: 27 additions & 0 deletions gems/decidim-templates/CVE-2023-36465.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
gem: decidim-templates
cve: 2023-36465
ghsa: 639h-86hw-qcjq
url: https://github.com/decidim/decidim/security/advisories/GHSA-639h-86hw-qcjq
title: Decidim has broken access control in templates
date: 2023-10-05
description: |
### Impact
The `templates` module doesn't enforce the correct permissions,
allowing any logged-in user to access to this functionality in
the administration panel. An attacker could use this vulnerability
to change, create or delete templates of surveys.
cvss_v3: 9.1
unaffected_versions:
- "< 0.23.2"
patched_versions:
- "~> 0.26.8"
- ">= 0.27.4"
related:
url:
- https://github.com/decidim/decidim/security/advisories/GHSA-639h-86hw-qcjq
- https://github.com/decidim/decidim/releases/tag/v0.26.8
- https://github.com/decidim/decidim/releases/tag/v0.27.4
- https://github.com/advisories/GHSA-639h-86hw-qcjq
notes: "No NVD url; No cvss_v2"
27 changes: 27 additions & 0 deletions gems/decidim/CVE-2023-36465.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
---
gem: decidim
cve: 2023-36465
ghsa: 639h-86hw-qcjq
url: https://github.com/decidim/decidim/security/advisories/GHSA-639h-86hw-qcjq
title: Decidim has broken access control in templates
date: 2023-10-05
description: |
### Impact
The `templates` module doesn't enforce the correct permissions,
allowing any logged-in user to access to this functionality in
the administration panel. An attacker could use this vulnerability
to change, create or delete templates of surveys.
cvss_v3: 9.1
unaffected_versions:
- "< 0.23.2"
patched_versions:
- "~> 0.26.8"
- ">= 0.27.4"
related:
url:
- https://github.com/decidim/decidim/security/advisories/GHSA-639h-86hw-qcjq
- https://github.com/decidim/decidim/releases/tag/v0.26.8
- https://github.com/decidim/decidim/releases/tag/v0.27.4
- https://github.com/advisories/GHSA-639h-86hw-qcjq
notes: "No NVD url; No cvss_v2"

0 comments on commit 14ff883

Please sign in to comment.