PT-2023-24663 · Ransack+2 · Ransack+2

·

CVE-2023-34090

·

Published

2023-07-11

·

Updated

2023-07-19

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Decidim versions prior to 0.27.3
Description Decidim, a participatory democracy framework written in Ruby on Rails, uses a third-party library named Ransack for filtering certain database collections. By default, this library allows filtering on all data attributes and associations, enabling an unauthenticated remote attacker to exfiltrate non-public data from the underlying database of a Decidim instance. This issue may lead to Sensitive Data Disclosure.
Recommendations For Decidim versions prior to 0.27.3, update to version 0.27.3 to resolve the issue. As a temporary workaround, consider disabling or unpublishing all meetings components from the application until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-34090
GHSA-JM79-9PM4-VRW9

Affected Products

Decidim
Ransack
Ruby On Rails