Loading...
Skip to main content

CVE-2023-51447

MEDIUM

Cross-site scripting (XSS) in the dynamic file uploads

Published February 20, 2024Updated February 20, 2024Source: osv

Summary

### Impact The dynamic file upload feature is subject to potential XSS attach in case the attacker manages to modify the file names of the records being uploaded to the server. This appears in sections where the user controls the file upload dialogs themselves and has the technical knowledge to change the file names through the dynamic upload endpoint. Therefore I believe it would require the attacker to control the whole session of the particular user but in any case, this needs to be fixed. Successful exploit of this vulneratibility would require the user to have successfully uploaded a file blob to the server with a malicious file name and then have the possibility to direct the other user to the edit page of the record where the attachment is attached. The users are able to craft the direct upload requests themselves controlling the file name that gets stored to the database as shown here: https://github.com/rails/rails/blob/a967d355c6fee9ad9b8bd115d43bc8b0fc207e7e/activestorage/app/controllers/active_storage/direct_uploads_controller.rb#L14 The attacker is able to change the filename e.g. to `<svg onload=alert('XSS')>` if they know how to craft these requests themselves. And then enter the returned blob ID to the form inputs manually by modifying the edit page source. Therefore, anywhere we display these strings, we should properly escape them. ### Patches PR #11612 fixes this problem both for 0.28.dev and 0.27.x. ### Workarounds Disable dynamic uploads for the instance, e.g. from proposals. ### References OWASP ASVS v4.0.3-5.1.3 ### Credits This issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by [Deloitte Finland](https://www2.deloitte.com/fi/fi.html).

Remediation

Upgrade to the fixed version using your package manager.

Bundler
Update decidim-core to 0.27.5 or later
gem install decidim-core -v 0.27.5
Bundler
Update decidim to 0.27.5 or later
gem install decidim -v 0.27.5

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (2)

PackageEcosystemAffectedFixed In
decidim-core
rubygems
0.27.0, 0.27.1, 0.27.2, 0.27.3 (+1 more)0.27.5
decidim
rubygems
0.27.0, 0.27.1, 0.27.2, 0.27.3 (+1 more)0.27.5

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-79
    Cross-site Scripting (XSS)MITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 6.3 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

Frequently Asked Questions

What is CVE-2023-51447?
Cross-site scripting (XSS) in the dynamic file uploads This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 6.3/10).
How do I check if my project is affected by CVE-2023-51447?
CVE-2023-51447 affects decidim-core and decidim. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2023-51447 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
6.3

Exploitation requires specific conditions or has limited impact. Remediate within weeks.

Also Known As

GHSA-9w99-78rj-hmxq

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies