PT-2026-58985 · Rubygems · Decidim-Verifications

Publicado

2026-07-13

·

Atualizado

2026-07-13

CVSS v3.1

6.0

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

Description

A participant manager can access and modify the CSV census record admin forms.

Technical description

The CSV census admin record-management surface under /admin/csv census/census logs does not enforce admin-only authorization before rendering or mutating Decidim::Verifications::CsvDatum.
A participant manager (which can only manage participants) can therefore open the admin forms, create or update census rows, and delete rows directly.
Reproduction steps:
  1. Sign in a participant admin and open http://localhost:3000/admin/csv census/census logs/new record in the browser. Confirm the create form loads even though the session is not a full admin.
decidim-census-01 decidim-census-02
Note that normal participant accounts were not able to access the CSV census records which is good.

Impact

Any participant admin can create, alter, or remove CSV census rows, which can corrupt verification data relied on by authorization workflows.

Patches

Workarounds

Disable Organization Census verification method

Reference

OWASP A01:2021 Broken Access Control

Credits

This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-Q79H-67VX-M9XG

Produtos afetados

Decidim-Verifications