Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Avo: Broken Access Control: Unauthorized Execution of Arbitrary Action Classes Across Resources
Vulnerability Description
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to insecure action lookup logic, an authenticated user can execute any Action class (descendants of Avo::BaseAction) on any resource, even if the action is not registered for that specific resource. This leads to Privilege Escalation and unauthorized data manipulation across the entire application. This issue has been patched in version 3.31.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
Avo 访问控制错误漏洞
Vulnerability Description
Avo是Avo开源的一个开源的 ruby on rails 管理面板创建框架。 Avo 3.31.2之前版本存在访问控制错误漏洞,该漏洞源于ActionsController中不安全的操作查找逻辑,可能导致认证用户在任何资源上执行任何操作类,即使该操作未注册到该特定资源,导致权限提升和整个应用程序中的未经授权数据操作。
CVSS Information
N/A
Vulnerability Type
N/A