CVE-2023-34102
published 2023-06-05CVE-2023-34102: Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.61%
74.8th percentile
Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record. This issue has been addressed in commit `ec117882d` which is expected to be included in subsequent releases. Users are advised to limit access to untrusted users until a new release is made.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avo-hq | avo | <= 2.33.2 | — |
| avo-hq | avo | — | — |
| avo-hq | avo | >= 0 < 2.33.3 | 2.33.3 |
| avo-hq | avo | 3.0.0.pre1 – 3.0.0.pre12 | — |
| avohq | avo | <= 2.33.2 | — |
| avohq | avo | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
avo possible unsafe reflection / partial DoS vulnerability
ghsa·2023-06-06
CVE-2023-34102 [HIGH] CWE-20 avo possible unsafe reflection / partial DoS vulnerability
avo possible unsafe reflection / partial DoS vulnerability
### Summary
The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record.
### Details
After reviewing the polymorphic field implementation and performing some black box approaches, we identified a potential security issue related to the use of safe_constantize / constantize. This Rails functionality is capable of searching for classes within the Rails context and returning the class for further use. Because Avo does not validate user input when updating or creating a new polymorphic resource, it is possible to create database entrie
OSV
avo possible unsafe reflection / partial DoS vulnerability
osv·2023-06-06
CVE-2023-34102 [HIGH] avo possible unsafe reflection / partial DoS vulnerability
avo possible unsafe reflection / partial DoS vulnerability
### Summary
The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record.
### Details
After reviewing the polymorphic field implementation and performing some black box approaches, we identified a potential security issue related to the use of safe_constantize / constantize. This Rails functionality is capable of searching for classes within the Rails context and returning the class for further use. Because Avo does not validate user input when updating or creating a new polymorphic resource, it is possible to create database entrie
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-05
Published