Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation
Vulnerability Description
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new path, but the actual write endpoint, POST /resources/:resource/:id/:related, does not run the same authorization check before mutating the association through Avo::AssociationsController#create. An authenticated low-privileged Avo user can bypass hidden or disabled attach controls and directly attach related records to a parent record by sending a crafted POST request, which can lead to privilege escalation and cross-tenant data exposure where associations represent authorization-bearing relationships. This issue is fixed in versions 3.32.1 and 4.0.0.beta.51.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
avo-hq avo 授权问题漏洞
Vulnerability Description
avo-hq avo是avo-hq的根据输入中"category1_names":"其他服务器产品"和"category2_names":"服务器",确认产品为服务器产品,但具体类型不够明确,无法输出更具体的定义短语。 avo-hq avo 3.32.1之前版本和4.0.0.beta.51之前版本存在授权问题漏洞,该漏洞源于关联附加工作流中授权检查不一致,可能导致已认证的低权限用户绕过隐藏或禁用的附加控件,通过特制POST请求直接附加相关记录,从而导致权限提升和跨租户数据泄露。
CVSS Information
N/A
Vulnerability Type
N/A