{"id":"CVE-2023-34102","aliases":["GHSA-86h2-2g4g-29qx"],"url":"https://o3.security/vulnerability/CVE-2023-34102","summary":"Possible unsafe reflection / partial denial of service in avo","details":"Avo is an open source ruby on rails admin panel creation framework. The polymorphic field type stores the classes to operate on when updating a record with user input, and does not validate them in the back end. This can lead to unexpected behavior, remote code execution, or application crashes when viewing a manipulated record. This issue has been addressed in commit `ec117882d` which is expected to be included in subsequent releases. Users are advised to limit access to untrusted users until a new release is made.","published":"2023-06-05T22:16:43.861Z","modified":"2026-08-12T03:51:27.933382273Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"},"epss":{"score":0.0161,"percentile":0.73665,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"avo","fixedVersion":"2.33.3"},{"ecosystem":"RubyGems","name":"avo","fixedVersion":null}],"fix":{"url":"https://github.com/avo-hq/avo/commit/ec117882ddb1b519481bdd046dc3cfa4474e6e17","label":"avo-hq/avo@ec11788"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34102.json"},{"type":"ADVISORY","url":"https://github.com/avo-hq/avo/security/advisories/GHSA-86h2-2g4g-29qx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34102"},{"type":"FIX","url":"https://github.com/avo-hq/avo/commit/ec117882ddb1b519481bdd046dc3cfa4474e6e17"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.933382273Z"}}