CVE-2023-34102 is a critical vulnerability affecting Avo, an open-source Ruby on Rails admin panel creation framework. It stems from a lack of backend validation for polymorphic field types, allowing attackers to manipulate records with user input. This can lead to remote code execution, application crashes, or other unexpected behavior when viewing compromised records. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low privileges and no user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. The EPSS score indicates a higher-than-average probability of exploitation compared to most CVEs. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion has been observed. A fix has been committed and is expected in future releases, with users advised to restrict untrusted access until an update is available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.33.2CPE matchmatch criteria | cpe:2.3:a:avohq:avo:*:*:*:*:*:ruby:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:avohq:avo:3.0.0:pre12:*:*:*:ruby:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.