CVE-2023-47634
low-risk
Published 2024-02-29
Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement. To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel. Versions 0.26.9, 0.27.5, and 0.28.0 contain a patch for this issue. As a workaround, disable the Endorsement feature in the components.
Do I need to act?
-
0.29% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.1/10
Low
NETWORK
/ HIGH complexity
Affected Products (1)
Decidim
Affected Vendors
References (8)
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.26.9
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.27.5
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.28.0
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.26.9
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.27.5
Release Notes
https://github.com/decidim/decidim/releases/tag/v0.28.0
17
/ 100
low-risk
Severity
11/34 · Low
Exploitability
1/34 · Minimal
Exposure
5/34 · Minimal