Decidim Cross-site Scripting vulnerability in the processes filter
Published: July 11, 2023
SECURITY IDENTIFIERS
- CVE: CVE-2023-34089 (NVD)
- GHSA: GHSA-5652-92r9-3fx9
- Vendor Advisory: https://github.com/decidim/decidim/security/advisories/GHSA-5652-92r9-3fx9
GEM
SEVERITY
CVSS v3.x: 8.1 (High)
UNAFFECTED VERSIONS
< 0.14.0
PATCHED VERSIONS
~> 0.26.6
>= 0.27.3
DESCRIPTION
Impact
The processes filter feature is susceptible to Cross-site scripting. This allows a remote attacker to execute JavaScript code in the context of a currently logged-in user. An attacker could use this vulnerability to make other users endorse or support proposals they have no intention of supporting or endorsing.
