Scanned identity-document images provided by participants and shown in the verification admin workflow are exposed through signed /rails/active_storage/disk/ URLs that can be fetched without any authenticated session.
Anyone who obtains one of those URLs can retrieve the document until the signature expires.
This issue comes from the verification admin UI exposing scanned documents through reusable Active Storage disk links. Verification-document images are rendered with variant_url(...), which produces signed /rails/active_storage/disk/... links instead of routing the file through an authorization-checking controller. Because Decidim configures Active Storage service URLs to remain valid for seven days, the URL itself becomes the credential for that period.
The affected files are verification_attachment blobs on Decidim::Authorization, and the admin review pages embed those signed URLs directly into the HTML for pending and confirmation views.
Reproduction steps:
Create a fresh verification document as a normal user. 1.1. Open http://localhost:3001/users/sign_in. 1.2. Open http://localhost:3001/id_documents/authorizations/new. 1.3. Submit an id_documents verification request with an image attachment.
Open the admin review page that renders the attachment. 2.1. Sign out. 2.2. Sign back in as [email protected]. 2.3. Try http://localhost:3001/admin/id_documents.
Harvest the signed Active Storage URL.
3.1. Open DevTools Network before loading the review page.
3.2. Reload the page.
3.3. Copy one request URL matching http://localhost:3001/rails/active_storage/disk/<SIGNED_TOKEN>/<FILENAME>.
Replay the file URL without any Decidim session. 4.1. Open a private window or a second browser where you are not signed in to Decidim. 4.2. Paste the exact copied /rails/active_storage/disk/... URL. 4.3. Confirm the verification image still loads.
See https://github.com/decidim/decidim/pull/16680
Disable the "Identity documents" verification
OWASP A01:2021 Broken Access Control
This issue was discovered in a security audit organized by the Decidim Association and made by Radically Open Security against Decidim financed by NGI.
| Software | From | Fixed in |
|---|---|---|
decidim-verifications
|
- | 0.30.9 |
decidim-verifications
|
0.31.0.rc1 | 0.31.5 |
decidim-verifications
|
0.32.0.rc1 | 0.32.0 |
A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.
CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.
A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.
Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.
Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.
SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.