A security vulnerability in Decidim versions 0.30.0+ allows private data exports to leak due to UUID collision issues. When UUIDs are converted to integers for ActiveStorage attachment record IDs, collisions can occur, causing one user's private export file to be attached to another user's export. The bug affects approximately 23 out of 1000 users theoretically. Patches are available in versions 0.30.4 and 0.31.0+. The workaround is to disable private exports until patching.
Table of contents
ADVISORIESGEMUNAFFECTED VERSIONSPATCHED VERSIONSDESCRIPTIONImpactWorkaroundsRELATED121 Impressions