HIGHRubyGems →
Possibility to circumvent the invitation token expiry period
Possibility to circumvent the invitation token expiry period
Affected packages
- decidim— 0.0.1.alpha3 → 0.26.9
- decidim-admin— 0.0.1.alpha3 → 0.26.9
- decidim-system— 0.0.1.alpha3 → 0.26.9
- devise_invitable— 0.4.rc3 → 2.0.9
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/decidim/decidim/security/advisories/GHSA-w3q8-m492-4pwp
- https://nvd.nist.gov/vuln/detail/CVE-2023-48220
- https://github.com/decidim/decidim/commit/073e60e2e4224dd81815a784002ebba30f2ebb34
- https://github.com/decidim/decidim/commit/b12800717a689c295a9ea680a38ca9f823d2c454
- https://github.com/scambra/devise_invitable/commit/94d859c7de0829bf63f679ae5dd3cab2b866a098
- https://github.com/decidim/decidim
- https://github.com/decidim/decidim/blob/d2d390578050772d1bdb6d731395f1afc39dcbfc/decidim-core/config/initializers/devise.rb#L134
- https://github.com/decidim/decidim/releases/tag/v0.26.9
- https://github.com/decidim/decidim/releases/tag/v0.27.5
- https://github.com/decidim/decidim/releases/tag/v0.28.0
- https://github.com/scambra/devise_invitable/blob/41f58970ff76fb64382a9b9ea1bd530f7c3adab2/lib/devise_invitable/models.rb#L198
Structured record: https://osv.dev/vulnerability/GHSA-w3q8-m492-4pwp
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta