github.com
https://github.com/avo-hq/avo CVE-2023-34102
HIGH
Possible unsafe reflection / partial denial of service in avo
Record summary
CVE-2023-34102 has a selected CVSS score of 8.3 (high).
Description
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record. This issue has been addressed in commit `ec117882d` which is expected to be included in subsequent releases. Users are advised to limit access to untrusted users until a new release is made.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 8, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | <= 2.33.2 | affected | |
| >= 3.0.0.pre1, <= 3.0.0.pre12 | affected | ||
| GitHub Advisory | Before 2.33.3 · Fixed in 2.33.3 | affected | |
| 3.0.0.pre1 to ≤ 3.0.0.pre12 | affected |
References
6github.com
https://github.com/avo-hq/avo/commit/ec117882ddb1b519481bdd046dc3cfa4474e6e17 github.com
https://github.com/avo-hq/avo/releases/tag/v2.33.3 github.comConfirmation
https://github.com/avo-hq/avo/security/advisories/GHSA-86h2-2g4g-29qx github.com
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/avo/CVE-2023-34102.yml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-34102