Loading HuntDB...

GHSA-r275-j57c-7mf2

GitHub Security Advisory

Race condition in Endorsements

✓ GitHub Reviewed LOW Has CVE

Advisory Details

### Impact

A race condition in the endorsement of resources (for instance, a proposal) allows a user to make more than once endorsement.

To exploit this vulnerability, the request to set an endorsement must be sent several times in parallel.

### Workarounds

Disable the Endorsement feature in the components.

Affected Packages

RubyGems decidim
Affected versions: 0.10.0 (fixed in 0.26.9)
RubyGems decidim
Affected versions: 0.27.0 (fixed in 0.27.5)

Related CVEs

Key Information

GHSA ID
GHSA-r275-j57c-7mf2
Published
February 20, 2024 6:02 PM
Last Modified
February 14, 2025 6:35 PM
CVSS Score
2.5 /10
Primary Ecosystem
RubyGems
Primary Package
decidim
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 13, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.