{"id":"GHSA-639h-86hw-qcjq","summary":"Decidim has broken access control in templates","details":"### Impact\n\nThe `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to this functionality in the administration panel. An attacker could use this vulnerability to change, create or delete templates of surveys.\n","aliases":["CVE-2023-36465"],"modified":"2023-11-08T05:25:53.975597Z","published":"2023-10-05T20:52:46Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-10-05T20:52:46Z","nvd_published_at":"2023-10-06T12:15:11Z","cwe_ids":["CWE-284","CWE-732"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/decidim/decidim/security/advisories/GHSA-639h-86hw-qcjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36465"},{"type":"PACKAGE","url":"https://github.com/decidim/decidim"},{"type":"WEB","url":"https://github.com/decidim/decidim/releases/tag/v0.26.8"},{"type":"WEB","url":"https://github.com/decidim/decidim/releases/tag/v0.27.4"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim-templates/CVE-2023-36465.yml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim/CVE-2023-36465.yml"}],"affected":[{"package":{"name":"decidim","ecosystem":"RubyGems","purl":"pkg:gem/decidim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.23.2"},{"fixed":"0.26.8"}]}],"versions":["0.23.2","0.23.3","0.23.4","0.23.5","0.23.6","0.24.0","0.24.0.rc1","0.24.0.rc2","0.24.1","0.24.2","0.24.3","0.25.0","0.25.0.rc1","0.25.0.rc2","0.25.0.rc3","0.25.0.rc4","0.25.1","0.25.2","0.26.0","0.26.0.rc2","0.26.1","0.26.2","0.26.3","0.26.4","0.26.5","0.26.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-639h-86hw-qcjq/GHSA-639h-86hw-qcjq.json"}},{"package":{"name":"decidim-templates","ecosystem":"RubyGems","purl":"pkg:gem/decidim-templates"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.23.2"},{"fixed":"0.26.8"}]}],"versions":["0.23.2","0.23.3","0.23.4","0.23.5","0.23.6","0.24.0","0.24.0.rc1","0.24.0.rc2","0.24.1","0.24.2","0.24.3","0.25.0","0.25.0.rc1","0.25.0.rc2","0.25.0.rc3","0.25.0.rc4","0.25.1","0.25.2","0.26.0","0.26.0.rc1","0.26.0.rc2","0.26.1","0.26.2","0.26.3","0.26.4","0.26.5","0.26.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-639h-86hw-qcjq/GHSA-639h-86hw-qcjq.json"}},{"package":{"name":"decidim-templates","ecosystem":"RubyGems","purl":"pkg:gem/decidim-templates"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.27.0"},{"fixed":"0.27.4"}]}],"versions":["0.27.0","0.27.1","0.27.2","0.27.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-639h-86hw-qcjq/GHSA-639h-86hw-qcjq.json"}},{"package":{"name":"decidim","ecosystem":"RubyGems","purl":"pkg:gem/decidim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.27.0"},{"fixed":"0.27.4"}]}],"versions":["0.27.0","0.27.1","0.27.2","0.27.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-639h-86hw-qcjq/GHSA-639h-86hw-qcjq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L"}]}