Decidim JWT-backed Authentication Vulnerability: Early Warning
An early warning has been issued regarding a vulnerability in Decidim where JWT-backed authentication can reportedly be replayed across different organizations, potentially allowing unauthorized access to sensitive information.
What happened
According to the advisory, it appears that a JSON Web Token (JWT) issued for one organization can be replayed successfully against another organization's API. This could allow an attacker to retrieve sensitive details from the targeted organization using the replayed JWT. The vulnerability is under investigation and the exact scope and impact are not yet fully understood.
Professional software engineers using Decidim are advised to assess their exposure by reviewing their use of JWT-backed authentication. As a precautionary measure, it is recommended to upgrade to the latest version of Decidim and disable JWT credentials on the system panel if immediate action is required. For more detailed information, consult the primary sources linked in the advisory.
How 0Day mitigates this
decidim is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.