CVE-2024-43415
Ruby vulnerability analysis and mitigation

Overview

A critical SQL injection vulnerability (CVE-2024-43415) was discovered in the decidimawesome-module versions <= v0.11.1 (> 0.9.0). The vulnerability exists in the papertrail/version-model component and allows authenticated admin users to manipulate SQL queries, potentially leading to unauthorized information disclosure, file system access, and command execution ([GitHub Advisory](https://github.com/decidim-ice/decidim-module-decidimawesome/security/advisories/GHSA-cxwf-qc32-375f), AIT Pentest).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and received a CVSS v3.1 base score of 9.0 (Critical). The security flaw exists in the adminroleactions method of the papertrail/version-model, where a raw SQL statement uses an interpolated variable without proper sanitization. The vulnerability can be exploited through the AdminAccountabilityController when the 'admins=true' parameter is included (GitHub Advisory).

Impact

The successful exploitation of this vulnerability could allow attackers to read sensitive information from the database, access and modify files on the filesystem, and potentially achieve remote code execution on the affected server. The impact is particularly severe as it affects core system functionalities and could lead to complete system compromise (AIT Pentest).

Mitigation and workarounds

Users are advised to update to version 0.10.3 or higher for the 0.10.x series, or version 0.11.2 or higher for the 0.11.x series. These patched versions include security fixes that properly sanitize SQL queries and prevent injection attacks (GitHub Advisory, AIT Pentest).

Additional resources


SourceThis report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-66568CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
CVE-2025-66567CRITICAL9.3
  • RubyRuby
  • ruby-saml
NoYesDec 09, 2025
GHSA-4249-gjr8-jpq3HIGH8.7
  • RubyRuby
  • prosemirror_to_html
NoYesNov 13, 2025
CVE-2025-64501HIGH7.6
  • RubyRuby
  • prosemirror_to_html
NoYesNov 10, 2025
GHSA-vfpf-xmwh-8m65HIGH7.6
  • RubyRuby
  • prosemirror_to_html
NoYesNov 07, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management