diff --git a/advisories/github-reviewed/2024/07/GHSA-qcj6-vxwx-4rqv/GHSA-qcj6-vxwx-4rqv.json b/advisories/github-reviewed/2024/07/GHSA-qcj6-vxwx-4rqv/GHSA-qcj6-vxwx-4rqv.json index 2a0c11a0d0d..1898b3ff0e5 100644 --- a/advisories/github-reviewed/2024/07/GHSA-qcj6-vxwx-4rqv/GHSA-qcj6-vxwx-4rqv.json +++ b/advisories/github-reviewed/2024/07/GHSA-qcj6-vxwx-4rqv/GHSA-qcj6-vxwx-4rqv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qcj6-vxwx-4rqv", - "modified": "2024-07-10T15:10:57Z", + "modified": "2024-07-10T18:00:18Z", "published": "2024-07-10T15:10:57Z", "aliases": [ "CVE-2024-27090" ], "summary": "Decidim vulnerable to data disclosure through the embed feature", - "details": "### Impact\n\nIf an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embedded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed. \n\n### Patches\n\nNot available\n\n### Workarounds\n\nDisallow access through your web server to the URLs finished with `/embed.html`\n", + "details": "### Impact\n\nIf an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embedded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed. \n\n### Patches\n\nversion 0.27.6\n\nhttps://github.com/decidim/decidim/commit/1756fa639ef393ca8e8bb16221cab2e2e7875705\n\n### Workarounds\n\nDisallow access through your web server to the URLs finished with `/embed.html`\n", "severity": [ { "type": "CVSS_V3",