devise_invitable
It adds support for send invitations by email (it requires to be authenticated) and accept the invitation by setting a password.
Activity
- Latest release
- 4mo ago
- Total releases
- 84
- Cadence
- ~2 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Dec 09, 2009
| Version | Released | |
|---|---|---|
2.0.12
patch
| ||
2.0.11
patch
| ||
2.0.10
patch
| ||
2.0.9
patch
| ||
2.0.8
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.7
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.6
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.5
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.4
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.5
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.4
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.5
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.6
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.5
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.4
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.2.1
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.8
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.7
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.6
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.5
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.4
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2023-48220
GHSA-w3q8-m492-4pwp
Feb 20, 2024
Possibility to circumvent the invitation token expiry period
5.7
/ 10
Medium
Network
High
High
Required
Unchanged
High
High
None
ImpactThe invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. When using the password reset functionality, the The only check done here is if the user has been invited but the code does not ensure that the pending invitation is still valid as defined by the
Decidim sets this configuration to The bug is in the PatchesUpdate
WorkaroundsThe invitations can be cancelled directly from the database by running the following command from the Rails console:
ReferencesOWASP ASVS V4.0.3-2.3.1 This bug has existed in the All versions since then are affected. This gem was first introduced at its version It was first introduced at its version CreditsThis issue was discovered in City of Helsinki's security audit against Decidim 0.27 done during September 2023. The security audit was implemented by Deloitte Finland. Affected versions
0.4.0
0.4.1
0.4.2
0.4.rc3
0.4.rc4
0.4.rc5
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
+ 50 more Show less
0.5.6
0.5.7
0.6.0
0.6.1
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.2.1
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.5
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
Fixed in
2.0.9
References
Updated Sep 10, 2026 · Source: OSV.dev |