CVE-2023-47634: Decidim has race condition in Endorsements
Impact
A race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement.
To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel. Workarounds
Disable the Endorsement feature in the components.
Other sources
Decidim is a participatory democracy framework. Starting in version 0.10.0 and prior to versions 0.26.9, 0.27.5, and 0.28.0, a race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement. To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel. Versions 0.26.9, 0.27.5, and 0.28.0 contain a patch for this issue. As a workaround, disable the Endorsement feature in the components.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47634?
CVE-2023-47634 is considered to have a moderate severity due to the potential for multiple endorsements to be made inappropriately.
How do I fix CVE-2023-47634?
To fix CVE-2023-47634, upgrade to Decidim version 0.26.9 or 0.27.5 or later.
What software is affected by CVE-2023-47634?
CVE-2023-47634 affects Decidim versions from 0.10.0 up to 0.26.9 and from 0.27.0 to 0.27.5.
What type of vulnerability is CVE-2023-47634?
CVE-2023-47634 is a race condition vulnerability that allows a user to make multiple endorsements.
Can I exploit CVE-2023-47634?
Yes, CVE-2023-47634 can be exploited by sending the endorsement request multiple times in parallel.