Security Advisory

CVE-2023-34102

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-06-05 22:16:43
Last updated 2025-01-08 15:48:32
Assigner GitHub_M
CVSS score 8.3
State PUBLISHED

Description

Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record. This issue has been addressed in commit `ec117882d` which is expected to be included in subsequent releases. Users are advised to limit access to untrusted users until a new release is made.