CVE-2024-27090
Last modified
CVE-2024-27090 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embbeded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an attacker can infer the slug or URL of an unpublished or private resource, and this resource can be embbeded (such as a Participatory Process, an Assembly, a Proposal, a Result, etc), then some data of this resource could be accessed. This vulnerability is fixed in 0.27.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-27090?
How severe is CVE-2024-27090?
How do I fix CVE-2024-27090?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-27085Discourse is an open source platform for community discussio…6.5
- CVE-2024-27086The MSAL library enabled acquisition of security tokens to c…3.9
- CVE-2024-27087Kirby is a content management system. The new link field int…5.4
- CVE-2024-27088es5-ext contains ECMAScript 5 extensions. Passing functions …5.5
- CVE-2024-27089Rejected reason: This candidate was withdrawn by its CNA. Fu…
- CVE-2024-2709A vulnerability was found in Tenda AC10U 15.03.06.49. It has…8.8
- CVE-2024-27091GeoNode is a geospatial content management system, a platfor…6.1
- CVE-2024-27092Hoppscotch is an API development ecosystem. Due to lack of …5.4
- CVE-2024-27093Minder is a Software Supply Chain Security Platform. In vers…7.5
- CVE-2024-27094OpenZeppelin Contracts is a library for secure smart contrac…7.4
- CVE-2024-27095Decidim is a participatory democracy framework. The admin pa…4.8
- CVE-2024-27096GLPI is a Free Asset and IT Management Software package, Dat…6.5
Are you affected by CVE-2024-27090?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
