CVE-2023-34102 - CVE House
Back to Database
Status published High CVE-2023-34102

Possible unsafe reflection / partial denial of service in avo

Vulnerability Description

Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record. This issue has been addressed in commit `ec117882d` which is expected to be included in subsequent releases. Users are advised to limit access to untrusted users until a new release is made.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-34102

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

avo
Vulnerable Versions:
<= 2.33.2, >= 3.0.0.pre1, <= 3.0.0.pre12

Timeline

Official Publish: June 5th, 2023
Last Modified: January 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

Weaknesses (CWE)