Impact
Decidim allows anyone who obtains a signed Active Storage URL to download a verification document without authenticating a Decidim session until the URL expires. The signed link itself acts as a credential for up to seven days, enabling undisclosed access to potentially sensitive user documents. This vulnerability results in a direct confidentiality breach.
Affected Systems
The issue affects the Decidim participatory democracy framework. Versions prior to 0.30.9, 0.31.0‑0.31.4, and 0.32.0.rc1 are vulnerable. The fix is included in releases 0.30.9, 0.31.5, and 0.32.0.rc2 and later.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability, although the EPSS score is not available. It is not listed in the CISA KEV catalog, suggesting no known active exploitation. Potential attackers can exploit the flaw by discovering or intercepting a signed URL from the admin review interface, then downloading the document within the signed‑link validity window. The lack of authentication checks on the asset route means the attack requires only access to the URL, making it relatively easy once the link is acquired.
OpenCVE Enrichment
Github GHSA